MediaWiki  master
MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider Class Reference

A primary authentication provider that uses the password field in the 'user' table. More...

Inheritance diagram for MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider:
Collaboration diagram for MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider:

Public Member Functions

 __construct ($params=[])
 accountCreationType ()
 Fetch the account-creation type. More...
 beginPrimaryAccountCreation ($user, $creator, array $reqs)
 Start an account creation flow. More...
 beginPrimaryAuthentication (array $reqs)
 Start an authentication flow. More...
 finishAccountCreation ($user, $creator, AuthenticationResponse $res)
 Post-creation callback. More...
 providerAllowsAuthenticationDataChange (AuthenticationRequest $req, $checkData=true)
 Validate a change of authentication data (e.g. More...
 providerChangeAuthenticationData (AuthenticationRequest $req)
 Change or remove authentication data (e.g. More...
 testForAccountCreation ($user, $creator, array $reqs)
 Determine whether an account creation may begin. More...
 testUserCanAuthenticate ($username)
 Test whether the named user can authenticate with this provider. More...
 testUserExists ($username, $flags=User::READ_NORMAL)
 Test whether the named user exists. More...
- Public Member Functions inherited from MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider
 __construct (array $params=[])
 getAuthenticationRequests ($action, array $options)
 Return the applicable list of AuthenticationRequests. More...
- Public Member Functions inherited from MediaWiki\Auth\AbstractPrimaryAuthenticationProvider
 autoCreatedAccount ($user, $source)
 Post-auto-creation callback. More...
 beginPrimaryAccountLink ($user, array $reqs)
 Start linking an account to an existing user. More...
 continuePrimaryAccountCreation ($user, $creator, array $reqs)
 Continue an account creation flow. More...
 continuePrimaryAccountLink ($user, array $reqs)
 Continue linking an account to an existing user. More...
 continuePrimaryAuthentication (array $reqs)
 Continue an authentication flow. More...
 finishAccountCreation ($user, $creator, AuthenticationResponse $response)
 Post-creation callback. More...
 postAccountCreation ($user, $creator, AuthenticationResponse $response)
 Post-creation callback. More...
 postAccountLink ($user, AuthenticationResponse $response)
 Post-link callback. More...
 postAuthentication ($user, AuthenticationResponse $response)
 Post-login callback. More...
 providerAllowsPropertyChange ($property)
 Determine whether a property can change. More...
 providerNormalizeUsername ($username)
 Normalize the username for authentication.Any two inputs that would result in the same user being authenticated should return the same string here, while inputs that would result in different users should return different strings.If possible, the best thing to do here is to return the canonicalized name of the local user account that would be used. If not, return something that would be invalid as a local username (e.g. wrap an email address in "<>", or append "#servicename" to the username passed to a third-party service).If the provider doesn't use a username at all in its AuthenticationRequests, return null. If the name is syntactically invalid, it's probably best to return null.
 providerRevokeAccessForUser ($username)
 Revoke the user's credentials.This may cause the user to no longer exist for the provider, or the user may continue to exist in a "disabled" state.The intention is that the named account will never again be usable for normal login (i.e. there is no way to undo the revocation of access).
 testForAccountCreation ($user, $creator, array $reqs)
 Determine whether an account creation may begin. More...
 testUserCanAuthenticate ($username)
 Test whether the named user can authenticate with this provider. More...
 testUserForCreation ($user, $autocreate, array $options=[])
 Determine whether an account may be created. More...
- Public Member Functions inherited from MediaWiki\Auth\AbstractAuthenticationProvider
 getUniqueId ()
 Return a unique identifier for this instance.This must be the same across requests. If multiple instances return the same ID, exceptions will be thrown from AuthManager.
 setConfig (Config $config)
 Set configuration. More...
 setLogger (LoggerInterface $logger)
 setManager (AuthManager $manager)
 Set AuthManager. More...

Protected Member Functions

 getPasswordResetData ($username, $row)
- Protected Member Functions inherited from MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider
 checkPasswordValidity ($username, $password)
 Check that the password is valid. More...
 failResponse (PasswordAuthenticationRequest $req)
 Return the appropriate response for failure. More...
 getNewPasswordExpiry ($username)
 Get expiration date for a new password, if any. More...
 getPassword ($hash)
 Get a Password object from the hash. More...
 getPasswordFactory ()
 Get the PasswordFactory. More...
 getPasswordResetData ($username, $data)
 Get password reset data, if any. More...
 setPasswordResetFlag ($username, Status $status, $data=null)
 Check if the password should be reset. More...

Protected Attributes

bool $loginOnly = false
 If true, this instance is for legacy logins only. More...
- Protected Attributes inherited from MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider
bool $authoritative
 Whether this provider should ABSTAIN (false) or FAIL (true) on password failure. More...
- Protected Attributes inherited from MediaWiki\Auth\AbstractAuthenticationProvider
Config $config
LoggerInterface $logger
AuthManager $manager

Additional Inherited Members

- Public Attributes inherited from MediaWiki\Auth\PrimaryAuthenticationProvider
const TYPE_CREATE = 'create'
 Provider can create accounts. More...
const TYPE_LINK = 'link'
 Provider can link to existing accounts elsewhere. More...
const TYPE_NONE = 'none'
 Provider cannot create or link to accounts. More...

Detailed Description

A primary authentication provider that uses the password field in the 'user' table.


Definition at line 31 of file LocalPasswordPrimaryAuthenticationProvider.php.

Constructor & Destructor Documentation

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::__construct (   $params = [])
  • loginOnly: If true, the local passwords are for legacy logins only: the local password will be invalidated when authentication is changed and new users will not have a valid local password set.

Definition at line 44 of file LocalPasswordPrimaryAuthenticationProvider.php.

References $params.

Member Function Documentation

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::accountCreationType ( )
MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::beginPrimaryAccountCreation (   $user,
array  $reqs 

Start an account creation flow.

User$userUser being created (not added to the database yet). This may become a "UserValue" in the future, or User may be refactored into such.
User$creatorUser doing the creation. This may become a "UserValue" in the future, or User may be refactored into such.
AuthenticationResponse Expected responses:
  • PASS: The user may be created. Secondary providers will now run.
  • FAIL: The user may not be created. Fail the creation process.
  • ABSTAIN: These $reqs are not handled. Some other primary provider may handle it.
  • UI: The $reqs are accepted, no other primary provider will run. Additional AuthenticationRequests are needed to complete the process.
  • REDIRECT: The $reqs are accepted, no other primary provider will run. Redirection to a third party is needed to complete the process.

Implements MediaWiki\Auth\PrimaryAuthenticationProvider.

Definition at line 282 of file LocalPasswordPrimaryAuthenticationProvider.php.

References $req, $ret, $user, MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider\accountCreationType(), class, MediaWiki\Auth\AuthenticationRequest\getRequestByClass(), MediaWiki\Auth\AuthenticationResponse\newAbstain(), and MediaWiki\Auth\AuthenticationResponse\newPass().

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::beginPrimaryAuthentication ( array  $reqs)

Start an authentication flow.

AuthenticationResponse Expected responses:
  • PASS: The user is authenticated. Secondary providers will now run.
  • FAIL: The user is not authenticated. Fail the authentication process.
  • ABSTAIN: These $reqs are not handled. Some other primary provider may handle it.
  • UI: The $reqs are accepted, no other primary provider will run. Additional AuthenticationRequests are needed to complete the process.
  • REDIRECT: The $reqs are accepted, no other primary provider will run. Redirection to a third party is needed to complete the process.

Implements MediaWiki\Auth\PrimaryAuthenticationProvider.

Definition at line 72 of file LocalPasswordPrimaryAuthenticationProvider.php.

References $req, $status, $username, MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\checkPasswordValidity(), class, DB_MASTER, MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\failResponse(), User\getCanonicalName(), MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\getPassword(), MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\getPasswordFactory(), MediaWiki\Auth\AuthenticationRequest\getRequestByClass(), MediaWiki\Auth\AuthenticationResponse\newAbstain(), MediaWiki\Auth\AuthenticationResponse\newFail(), MediaWiki\Auth\AuthenticationResponse\newPass(), MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\setPasswordResetFlag(), and wfGetDB().

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::finishAccountCreation (   $user,
AuthenticationResponse  $response 

Post-creation callback.

Called after the user is added to the database, before secondary authentication providers are run.

User$userUser being created (has been added to the database now). This may become a "UserValue" in the future, or User may be refactored into such.
User$creatorUser doing the creation. This may become a "UserValue" in the future, or User may be refactored into such.
AuthenticationResponse$responsePASS response returned earlier
string|null 'newusers' log subtype to use for logging the account creation. If null, either 'create' or 'create2' will be used depending on $creator.

Implements MediaWiki\Auth\PrimaryAuthenticationProvider.

Definition at line 304 of file LocalPasswordPrimaryAuthenticationProvider.php.

References MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider\accountCreationType(), and MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider\providerChangeAuthenticationData().

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::getPasswordResetData (   $username,
MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::providerAllowsAuthenticationDataChange ( AuthenticationRequest  $req,
  $checkData = true 

Validate a change of authentication data (e.g.


Return StatusValue::newGood( 'ignored' ) if you don't support this AuthenticationRequest type.

bool$checkDataIf false, $req hasn't been loaded from the submission so checks on user-submitted fields should be skipped. $req->username is considered user-submitted for this purpose, even if it cannot be changed via $req->loadFromSubmission.

Implements MediaWiki\Auth\PrimaryAuthenticationProvider.

Definition at line 191 of file LocalPasswordPrimaryAuthenticationProvider.php.

References $username, MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\checkPasswordValidity(), class, DB_MASTER, User\getCanonicalName(), StatusValue\newGood(), and wfGetDB().

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::providerChangeAuthenticationData ( AuthenticationRequest  $req)

Change or remove authentication data (e.g.


If $req was returned for AuthManager::ACTION_CHANGE, the corresponding credentials should result in a successful login in the future.

If $req was returned for AuthManager::ACTION_REMOVE, the corresponding credentials should no longer result in a successful login.


Implements MediaWiki\Auth\PrimaryAuthenticationProvider.

Definition at line 230 of file LocalPasswordPrimaryAuthenticationProvider.php.

References $username, class, DB_MASTER, User\getCanonicalName(), MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\getNewPasswordExpiry(), MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\getPasswordFactory(), and wfGetDB().

Referenced by MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider\finishAccountCreation().

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::testForAccountCreation (   $user,
array  $reqs 

Determine whether an account creation may begin.

Called from AuthManager::beginAccountCreation()

No need to test if the account exists, AuthManager checks that
User$userUser being created (not added to the database yet). This may become a "UserValue" in the future, or User may be refactored into such.
User$creatorUser doing the creation. This may become a "UserValue" in the future, or User may be refactored into such.

Implements MediaWiki\Auth\PrimaryAuthenticationProvider.

Definition at line 266 of file LocalPasswordPrimaryAuthenticationProvider.php.

References $req, $ret, $user, MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\checkPasswordValidity(), class, MediaWiki\Auth\AuthenticationRequest\getRequestByClass(), and StatusValue\newGood().

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::testUserCanAuthenticate (   $username)

Test whether the named user can authenticate with this provider.


Implements MediaWiki\Auth\PrimaryAuthenticationProvider.

Definition at line 149 of file LocalPasswordPrimaryAuthenticationProvider.php.

References $username, DB_MASTER, User\getCanonicalName(), MediaWiki\Auth\AbstractPasswordPrimaryAuthenticationProvider\getPassword(), and wfGetDB().

MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::testUserExists (   $username,
  $flags = User::READ_NORMAL 

Test whether the named user exists.

int$flagsBitfield of User:READ_* constants

Implements MediaWiki\Auth\PrimaryAuthenticationProvider.

Definition at line 175 of file LocalPasswordPrimaryAuthenticationProvider.php.

References $flags, $options, $username, User\getCanonicalName(), DBAccessObjectUtils\getDBOptions(), list, and wfGetDB().

Member Data Documentation

bool MediaWiki\Auth\LocalPasswordPrimaryAuthenticationProvider::$loginOnly = false

If true, this instance is for legacy logins only.

Definition at line 36 of file LocalPasswordPrimaryAuthenticationProvider.php.

The documentation for this class was generated from the following file: