patrickpollet / mahara_plugin_auth_cas

3 stars 10 forks source link

phpCAS 1.3.3 migration due to security issues #6

Closed gaudreaj closed 10 years ago

gaudreaj commented 10 years ago

Hi Patrick,

It seems the phpCAS version 1.1.3, actually used by the plugin, isn't supported anymore and has many security issues (See https://wiki.jasig.org/display/casc/phpcas).

I've upgraded your plugin to use the latest version of the phpCAS library (1.3.3). I didn't have the time to check every functionalities but I can assure that basic authentication (Without proxy or certificate) is working on login/logout. Cron is working but I haven't checked the sync.

Hope it helps to anybody who's currently using this plugin.

Jean-Philippe