Linux workstation

openSUSE Tumbleweed native package

perl-Apache-AuthCookie

Perl Authentication and Authorization via cookies

Packages / openSUSE Tumbleweed / Unspecified / perl-Apache-AuthCookie

[Source: perl-Apache-AuthCookie]

Package: perl-Apache-AuthCookie (3.31-1.18)

[Project overview: libapache2-authcookie-perl]

External Resources:

Homepage: [metacpan.org]

Perl Authentication and Authorization via cookies

*Apache::AuthCookie* allows you to intercept a user's first unauthenticated access to a protected document. The user will be presented with a custom form where they can enter authentication credentials. The credentials are posted to the server where AuthCookie verifies them and returns a session key. The session key is returned to the user's browser as a cookie. As a cookie, the browser will pass the session key on every subsequent accesses. AuthCookie will verify the session key and re-authenticate the user. All you have to do is write a custom module that inherits from AuthCookie. Your module is a class which implements two methods: * 'authen_cred()' Verify the user-supplied credentials and return a session key. The session key can be any string - often you'll use some string containing username, timeout info, and any other information you need to determine access to documents, and append a one-way hash of those values together with some secret key. * 'authen_ses_key()' Verify the session key (previously generated by 'authen_cred()', possibly during a previous request) and return the user ID. This user ID will be fed to '$r->connection->user()' to set Apache's idea of who's logged in. By using AuthCookie versus Apache's built-in AuthBasic you can design your own authentication system. There are several benefits. * 1. The client doesn't *have* to pass the user credentials on every subsequent access. If you're using passwords, this means that the password can be sent on the first request only, and subsequent requests don't need to send this (potentially sensitive) information. This is known as "ticket-based" authentication. * 2. When you determine that the client should stop using the credentials/session key, the server can tell the client to delete the cookie. Letting users "log out" is a notoriously impossible-to-solve problem of AuthBasic. * 3. AuthBasic dialog boxes are ugly. You can design your own HTML login forms when you use AuthCookie. * 4. You can specify the domain of a cookie using PerlSetVar commands. For instance, if your AuthName is 'WhatEver', you can put the command PerlSetVar WhatEverDomain .yourhost.com into your server setup file and your access cookies will span all hosts ending in '.yourhost.com'. * 5. You can optionally specify the name of your cookie using the 'CookieName' directive. For instance, if your AuthName is 'WhatEver', you can put the command PerlSetVar WhatEverCookieName MyCustomName into your server setup file and your cookies for this AuthCookie realm will be named MyCustomName. Default is AuthType_AuthName. * 6. By default users must satisfy ALL of the 'require' directives. If you want authentication to succeed if ANY 'require' directives are met, use the 'Satisfy' directive. For instance, if your AuthName is 'WhatEver', you can put the command PerlSetVar WhatEverSatisfy Any into your server startup file and authentication for this realm will succeed if ANY of the 'require' directives are met. This is the flow of the authentication handler, less the details of the redirects. Two REDIRECT's are used to keep the client from displaying the user's credentials in the Location field. They don't really change AuthCookie's model, but they do add another round-trip request to the client. (-----------------------) +---------------------------------+ ( Request a protected ) | AuthCookie sets custom error | ( page, but user hasn't )---->| document and returns | ( authenticated (no ) | FORBIDDEN. Apache abandons | ( session key cookie) ) | current request and creates sub | (-----------------------) | request for the error document. |<-+ | Error document is a script that | | | generates a form where the user | | return | enters authentication | | ^------------------->| credentials (login & password). | | / \ False +---------------------------------+ | / \ | | / \ | | / \ V | / \ +---------------------------------+ | / Pass \ | User's client submits this form | | / user's \ | to the LOGIN URL, which calls | | | credentials |<------------| AuthCookie->login(). | | \ to / +---------------------------------+ | \authen_cred/ | \ function/ | \ / | \ / | \ / +------------------------------------+ | \ / return | Authen cred returns a session | +--+ V------------->| key which is opaque to AuthCookie.*| | True +------------------------------------+ | | | +--------------------+ | +---------------+ | | | | If we had a | V | V | cookie, add | +----------------------------+ r | ^ | a Set-Cookie | | If we didn't have a session| e |T / \ | header to | | key cookie, add a | t |r / \ | override the | | Set-Cookie header with this| u |u / \ | invalid cookie| | session key. Client then | r |e / \ +---------------+ | returns session key with | n | / pass \ ^ | successive requests | | / session \ | +----------------------------+ | / key to \ return | | +-| authen_ses_key|------------+ V \ / False +-----------------------------------+ \ / | Tell Apache to set Expires header,| \ / | set user to user ID returned by | \ / | authen_ses_key, set authentication| \ / | to our type (e.g. AuthCookie). | \ / +-----------------------------------+ \ / V (---------------------) ^ ( Request a protected ) | ( page, user has a )--------------+ ( session key cookie ) (---------------------) * The session key that the client gets can be anything you want. For example, encrypted information about the user, a hash of the username and password (similar in function to Digest authentication), or the user name and password in plain text (similar in function to HTTP Basic authentication). The only requirement is that the authen_ses_key function that you create must be able to determine if this session_key is valid and map it back to the originally authenticated user ID.

Other Packages Related to perl-Apache-AuthCookie:

  • dep: perl(:MODULE_COMPAT_5.44.0)

    Package not available

  • dep: perl(Class::Load) (>= 0.03)

    Package not available

  • dep: perl(HTTP::Body)

    Package not available

  • dep: perl(Hash::MultiValue)

    Package not available

  • dep: perl(Test::More) (>= 0.94)

    Package not available

  • dep: perl(URI) (>= 1.36)

    Package not available

  • dep: perl(WWW::Form::UrlEncoded)

    Package not available

  • rec: perl(WWW::Form::UrlEncoded::XS)

    Package not available

Download perl-Apache-AuthCookie

ArchitecturePackage SizeInstalled SizeFiles
noarch105 KiB222 KiB[list of files]

Package file paths (34)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

  • /usr/lib/perl5/vendor_perl/5.44.0/Apache
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache2
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache2_4
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache2_4/AuthCookie.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache2/AuthCookie
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache2/AuthCookie/Base.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache2/AuthCookie/Params.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache2/AuthCookie.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/AuthCookie
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/AuthCookie/FAQ.pod
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/AuthCookie/Params
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/AuthCookie/Params/Base.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/AuthCookie/Params/CGI.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/AuthCookie/Params.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/AuthCookie.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/AuthCookie/Util.pm
  • /usr/lib/perl5/vendor_perl/5.44.0/Apache/README.apache-2.4.pod
  • /usr/share/doc/packages/perl-Apache-AuthCookie
  • /usr/share/doc/packages/perl-Apache-AuthCookie/Changes
  • /usr/share/doc/packages/perl-Apache-AuthCookie/README
  • /usr/share/doc/packages/perl-Apache-AuthCookie/README.modperl2
  • /usr/share/licenses/perl-Apache-AuthCookie
  • /usr/share/licenses/perl-Apache-AuthCookie/LICENSE
  • /usr/share/man/man3/Apache2_4::AuthCookie.3pm.gz
  • /usr/share/man/man3/Apache2::AuthCookie.3pm.gz
  • /usr/share/man/man3/Apache2::AuthCookie::Base.3pm.gz
  • /usr/share/man/man3/Apache2::AuthCookie::Params.3pm.gz
  • /usr/share/man/man3/Apache::AuthCookie.3pm.gz
  • /usr/share/man/man3/Apache::AuthCookie::FAQ.3pm.gz
  • /usr/share/man/man3/Apache::AuthCookie::Params.3pm.gz
  • /usr/share/man/man3/Apache::AuthCookie::Params::Base.3pm.gz
  • /usr/share/man/man3/Apache::AuthCookie::Params::CGI.3pm.gz
  • /usr/share/man/man3/Apache::AuthCookie::Util.3pm.gz
  • /usr/share/man/man3/Apache::README.apache-2.4.3pm.gz

Field source: openSUSE Tumbleweed OSS revision tumbleweed-oss-multiarch:4db10cdde3ad82c7e22be35753c9e164b4bdd30f92db4aee17a0d4c94c5f902f

Use this package

OpenFactory can boot this operating system in a browser VM, or start a build that includes the native package name from this record.

Versions, suites, and repositories

Each row is recorded package-index metadata for one version, architecture, suite, and repository. Names, URLs, and sizes are source-reported; a link is a potentially mutable retrieval location, not an OpenFactory redistribution claim or proof that OpenFactory retained the artifact bytes.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
3.31-1.18tumbleweed / ossnoarchopenSUSE Tumbleweed · OSS · multi-architecture105 KiB222 KiBnoarch/perl-Apache-AuthCookie-3.31-1.18.noarch.rpm

Field source: openSUSE Tumbleweed OSS revision tumbleweed-oss-multiarch:4db10cdde3ad82c7e22be35753c9e164b4bdd30f92db4aee17a0d4c94c5f902f

Checksums and observation dates

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

Catalog record completeness

The completeness score measures metadata coverage, not software quality, security, compatibility, or suitability.

Summary and description
25/25
Artifact path and source digest
25/25
Dependency metadata
15/15
Package-file index
15/15
Homepage
5/5
License text
5/5
Source package or maintainer
10/10

Recorded total: 100/100

Field source: openSUSE Tumbleweed OSS revision tumbleweed-oss-multiarch:4db10cdde3ad82c7e22be35753c9e164b4bdd30f92db4aee17a0d4c94c5f902f. The cross-OS mapping is catalog-derived from the source-reported homepage; it does not establish authorship or publisher identity

Sources and provenance

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision tumbleweed-oss-multiarch:4db10cdde3ad82c7e22be35753c9e164b4bdd30f92db4aee17a0d4c94c5f902f

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    4db10cdde3ad82c7e22be35753c9e164b4bdd30f92db4aee17a0d4c94c5f902f
    Signer fingerprint
    AD485664E901B867051AB15F35A2F86E29B700A4
    Keyring revision
    opensuse-project-signing-key.asc
    SHA-256 b5745739ebfb95b25b8e810f9bcb847fe750ccda598bd85f02f0e974599a6d7e
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: Not recorded
    Expected SHA-256: Not recorded
    Observed SHA-256: Not recorded
    Result: match verified

perl-Apache-AuthCookie Package for openSUSE Tumbleweed | OpenFactory