Modified: pear/packages/Bugtracker/trunk/include/functions.inc =================================================================== --- pear/packages/Bugtracker/trunk/include/functions.inc 2009-08-13 16:29:31 UTC (rev 287256) +++ pear/packages/Bugtracker/trunk/include/functions.inc 2009-08-13 16:30:38 UTC (rev 287257) @@ -1410,7 +1410,7 @@ { if (DEVBOX === true) { echo '
'; - var_dump($to, $subject, $message, $headers, $parameters); + var_dump(htmlspecialchars($to), htmlspecialchars($subject), htmlspecialchars($message), htmlspecialchars($headers), htmlspecialchars($parameters)); echo ''; return true; } Modified: pear/packages/Bugtracker/trunk/site/patch-add.php =================================================================== --- pear/packages/Bugtracker/trunk/site/patch-add.php 2009-08-13 16:29:31 UTC (rev 287256) +++ pear/packages/Bugtracker/trunk/site/patch-add.php 2009-08-13 16:30:38 UTC (rev 287257) @@ -42,18 +42,16 @@ require_once "{$ROOT_DIR}/include/classes/bug_patchtracker.php"; $patchinfo = new Bug_Patchtracker; +$patch_name = (!empty($_POST['name']) && is_string($_POST['name'])) ? $_POST['name'] : ''; +$patch_name_url = urlencode($patch_name); + if (isset($_POST['addpatch'])) { if (!isset($_POST['obsoleted'])) { $_POST['obsoleted'] = array(); } - $email = isset($_POST['email']) ? $_POST['email'] : ''; - - if (!isset($_POST['name']) || empty($_POST['name']) || !is_string($_POST['name'])) { - if (!is_string($_POST['name'])) { - $_POST['name'] = ''; - } - $name = $_POST['name']; + // Check that patch name is given (required always) + if (empty($patch_name)) { $patches = $patchinfo->listPatches($bug_id); $errors[] = 'No patch name entered'; include "{$ROOT_DIR}/templates/addpatch.php"; @@ -64,7 +62,9 @@ try { $errors = array(); - if (!is_valid_email($_POST['email'])) { + $email = isset($_POST['email']) ? $_POST['email'] : ''; + + if (!is_valid_email($email)) { $errors[] = 'Email address must be valid!'; } @@ -84,55 +84,43 @@ } PEAR::pushErrorHandling(PEAR_ERROR_RETURN); - $e = $patchinfo->attach($bug_id, 'patch', $_POST['name'], $_POST['email'], $_POST['obsoleted']); + $e = $patchinfo->attach($bug_id, 'patch', $patch_name, $email, $_POST['obsoleted']); PEAR::popErrorHandling(); if (PEAR::isError($e)) { - if (!is_string($_POST['name'])) { - $_POST['name'] = ''; - } - $name = $_POST['name']; $patches = $patchinfo->listPatches($bug_id); $errors[] = $e->getMessage(); - $errors[] = 'Could not attach patch "' . htmlspecialchars($_POST['name']) . '" to Bug #' . $bug_id; + $errors[] = 'Could not attach patch "' . htmlspecialchars($patch_name) . '" to Bug #' . $bug_id; include "{$ROOT_DIR}/templates/addpatch.php"; exit; } - redirect("patch-display.php?bug={$bug_id}&patch=" . urlencode($_POST['name']) . "&revision={$e}"); + redirect("patch-display.php?bug={$bug_id}&patch={$patch_name_url}&revision={$e}"); exit; } catch (Exception $e) { - if (!is_string($_POST['name'])) { - $_POST['name'] = ''; - } - $name = $_POST['name']; $patches = $patchinfo->listPatches($bug_id); include "{$ROOT_DIR}/templates/addpatch.php"; exit; } + } else { + $email = $auth_user->email; } PEAR::pushErrorHandling(PEAR_ERROR_RETURN); - $e = $patchinfo->attach($bug_id, 'patch', $_POST['name'], $auth_user->handle, $_POST['obsoleted']); + $e = $patchinfo->attach($bug_id, 'patch', $patch_name, $auth_user->email, $_POST['obsoleted']); PEAR::popErrorHandling(); if (PEAR::isError($e)) { - if (!is_string($_POST['name'])) { - $_POST['name'] = ''; - } - $name = $_POST['name']; $patches = $patchinfo->listPatches($bug_id); $errors = array($e->getMessage(), 'Could not attach patch "' . - htmlspecialchars($_POST['name']) . + htmlspecialchars($patch_name) . '" to Bug #' . $bug_id); include "{$ROOT_DIR}/templates/addpatch.php"; exit; } // Add a comment to the bug report. - $patch_name = $_POST['name']; - $patch_name_url = urlencode($patch_name); - $patch_url = "http://{$site_url}{$basedir}/{$url}patch-display.php?bug={$bug_id}&patch={$patch_name_url}&revision={$e}&display=1"; + $patch_url = "http://{$site_url}{$basedir}/patch-display.php?bug={$bug_id}&patch={$patch_name_url}&revision={$e}&display=1"; $text = <<
If you submitted this patch, please check your email.
' . - 'If you do not have a confirmation message, click here to re-send or write a message to' . - ' ' . PEAR_DEV_EMAIL . ' asking for manual approval of your account.
'; - response_footer(); - exit; - } - require_once 'HTTP.php'; if (isset($_GET['download'])) { header('Last-modified: ' . HTTP::date(filemtime($path))); header('Content-type: application/octet-stream'); - header('Content-disposition: attachment; filename="' . $patch . '.patch.txt"'); + header('Content-disposition: attachment; filename="' . $patch_name . '.patch.txt"'); header('Content-length: '.filesize($path)); readfile($path); exit; } - $patchcontents = $patchinfo->getPatch($buginfo['id'], $patch, $revision); + $patchcontents = $patchinfo->getPatch($buginfo['id'], $patch_name, $revision); if (PEAR::isError($patchcontents)) { response_header('Error :: Cannot retrieve patch'); @@ -79,19 +70,18 @@ exit; } - $package = $buginfo['package_name']; - $bug = $buginfo['id']; - $handle = $patchinfo->getDeveloper($bug, $patch, $revision); - $obsoletedby = $patchinfo->getObsoletingPatches($bug, $patch, $revision); - $obsoletes = $patchinfo->getObsoletePatches($bug, $patch, $revision); - $patches = $patchinfo->listPatches($bug); - $revisions = $patchinfo->listRevisions($bug, $patch); + $package_name = $buginfo['package_name']; + $handle = $patchinfo->getDeveloper($bug_id, $patch_name, $revision); + $obsoletedby = $patchinfo->getObsoletingPatches($bug_id, $patch_name, $revision); + $obsoletes = $patchinfo->getObsoletePatches($bug_id, $patch_name, $revision); + $patches = $patchinfo->listPatches($bug_id); + $revisions = $patchinfo->listRevisions($bug_id, $patch_name); - response_header('Bug #' . clean($bug) . ' :: Patches'); + response_header("Bug #{$bug_id} :: Patches"); include "{$ROOT_DIR}/templates/listpatches.php"; if (isset($_GET['diff']) && $_GET['diff'] && isset($_GET['old']) && is_numeric($_GET['old'])) { - $old = $patchinfo->getPatchFullpath($bug_id, $patch, $_GET['old']); + $old = $patchinfo->getPatchFullpath($bug_id, $patch_name, $_GET['old']); $new = $path; if (!realpath($old) || !realpath($new)) { response_header('Error :: Cannot retrieve patch'); @@ -114,8 +104,7 @@ exit; } -$bug = $buginfo['id']; -$patches = $patchinfo->listPatches($bug); -response_header('Bug #' . clean($bug) . ' :: Patches'); +$patches = $patchinfo->listPatches($bug_id); +response_header("Bug #{$bug_id} :: Patches"); include "{$ROOT_DIR}/templates/listpatches.php"; response_footer(); Modified: pear/packages/Bugtracker/trunk/templates/addpatch.php =================================================================== --- pear/packages/Bugtracker/trunk/templates/addpatch.php 2009-08-13 16:29:31 UTC (rev 287256) +++ pear/packages/Bugtracker/trunk/templates/addpatch.php 2009-08-13 16:30:38 UTC (rev 287257) @@ -1,7 +1,7 @@ -| - Return to Bug # + Return to Bug # | Add a Patch | |
| - Patch + Patch |
- revision
- by - + revision + by + |
|---|