MD5_Final(md5buf, &md5ctx);
digest_md5_to_hex(md5buf, md5hex);
+ memset(result, 0, resultlen);
strncpy(result, md5hex, resultlen-1);
- result[resultlen-1] = '\0';
}
int
digest_is_valid(const char *our_realm, const char *password,
const char *our_nonce, const char *method,
- const char *authorization)
+ const char *our_uri, const char *authorization)
{
char *auth;
char *current;
else *last = '\0';
/* Store value if it is relevant */
- if (!strncmp("username=\"", first, 10))
+ if (!strncmp("username=\"", first, 10)) {
username = first+10;
- if (!strncmp("realm=\"", first, 7))
+ } else if (!strncmp("realm=\"", first, 7)) {
realm = first+7;
- if (!strncmp("nonce=\"", first, 7))
+ } else if (!strncmp("nonce=\"", first, 7)) {
nonce = first+7;
- if (!strncmp("uri=\"", first, 5))
+ } else if (!strncmp("uri=\"", first, 5)) {
uri = first+5;
- if (!strncmp("response=\"", first, 10))
+ } else if (!strncmp("response=\"", first, 10)) {
response = first+10;
+ }
+ }
+
+ if (!username || !realm || !nonce || !uri || !response) {
+ free(auth);
+ return 0;
+ }
+ if (strcmp(realm, our_realm) || strcmp(nonce, our_nonce) || strcmp(uri, our_uri)) {
+ free(auth);
+ return 0;
}
/* Calculate our response */