Modified: web/php-bugs/trunk/include/functions.php =================================================================== --- web/php-bugs/trunk/include/functions.php 2010-03-09 18:20:37 UTC (rev 296004) +++ web/php-bugs/trunk/include/functions.php 2010-03-09 19:00:00 UTC (rev 296005) @@ -1381,7 +1381,8 @@ $query = 'SELECT b.id, b.package_name, b.bug_type, b.email, b.reporter_name, b.sdesc, b.ldesc, b.php_version, b.php_os, - b.status, b.ts1, b.ts2, b.assign, UNIX_TIMESTAMP(b.ts1) AS submitted, + b.status, b.ts1, b.ts2, b.assign, + UNIX_TIMESTAMP(b.ts1) AS submitted, UNIX_TIMESTAMP(b.ts2) AS modified, COUNT(bug=b.id) AS votes, SUM(reproduced) AS reproduced, SUM(tried) AS tried, Modified: web/php-bugs/trunk/include/query.php =================================================================== --- web/php-bugs/trunk/include/query.php 2010-03-09 18:20:37 UTC (rev 296004) +++ web/php-bugs/trunk/include/query.php 2010-03-09 19:00:00 UTC (rev 296005) @@ -48,8 +48,8 @@ SELECT SQL_CALC_FOUND_ROWS bugdb.*, TO_DAYS(NOW())-TO_DAYS(bugdb.ts2) AS unchanged, - UNIX_TIMESTAMP(ts1) as ts1a, - UNIX_TIMESTAMP(ts2) as ts2a + UNIX_TIMESTAMP(ts1) AS submitted, + UNIX_TIMESTAMP(ts2) AS modified FROM bugdb '; Modified: web/php-bugs/trunk/www/rss/rdf.php =================================================================== --- web/php-bugs/trunk/www/rss/rdf.php 2010-03-09 18:20:37 UTC (rev 296004) +++ web/php-bugs/trunk/www/rss/rdf.php 2010-03-09 19:00:00 UTC (rev 296005) @@ -1,14 +1,15 @@ ' . utf8_encode(htmlspecialchars($desc)) . ''; +$desc = '
' . clean($desc) . '
'; $state = 'http://xmlns.com/baetle/#Open'; switch ($bug['status']) { @@ -62,7 +63,7 @@ <?php echo $bug['package_name']; ?> Bug #<?php echo intval($bug['id']); ?> - + en-us -webmaster@lists.php.net @@ -84,17 +85,17 @@ - - + + - <?php echo utf8_encode(htmlspecialchars(substr($bug['email'], 0, strpos($bug['email'], '@')))) . "@... [{$bug['ts1']}]"; ?> + <?php echo clean(substr($bug['email'], 0, strpos($bug['email'], '@'))), "@... [{$bug['ts1']}]"; ?> ]]> ]]> - + # - ]]> - ]]> + ]]> + ]]> Modified: web/php-bugs/trunk/www/rss/rss.php =================================================================== --- web/php-bugs/trunk/www/rss/rss.php 2010-03-09 18:20:37 UTC (rev 296004) +++ web/php-bugs/trunk/www/rss/rss.php 2010-03-09 19:00:00 UTC (rev 296005) @@ -7,37 +7,36 @@ } else { $desc .= substr($bug['email'], 0, strpos($bug['email'], '@')) . "@...\n"; } -$desc .= date(DATE_ATOM, $bug['ts1a']) . "\n"; +$desc .= date(DATE_RSS, $bug['submitted']) . "\n"; $desc .= "PHP: {$bug['php_version']}, OS: {$bug['php_os']}, Package Version: {$bug['package_version']}\n\n"; $desc .= $bug['ldesc']; -$desc = '
' . utf8_encode(htmlspecialchars($desc)) . '
'; - +$desc = '
' . clean($desc) . '
'; + ?> - + <?php echo "{$bug['package_name']} Bug #{$bug['id']}"; ?> - - - - + + + + " rel="self" type="application/rss+xml" /> - <?php echo utf8_encode(($bug['handle'])? htmlspecialchars($bug['handle']):htmlspecialchars(substr($bug['email'], 0, strpos($bug['email'], '@'))) . "@... [{$bug['ts1']}]"); ?> + <?php echo ($bug['handle']) ? clean($bug['handle']) : clean(substr($bug['email'], 0, strpos($bug['email'], '@'))), "@... [{$bug['ts1']}]"; ?> ]]> - + - - <?php echo utf8_encode( ($comment['handle'])? htmlspecialchars($comment['handle']) . " [$displayts]": htmlspecialchars(substr($comment['email'], 0, strpos($comment['email'], '@')) . "@... [$displayts]")); ?> - ".utf8_encode(htmlspecialchars($comment['comment'])).""; ?>]]> - - + <?php echo clean(($comment['handle']) ? $comment['handle'] . " [$displayts]" : substr($comment['email'], 0, strpos($comment['email'], '@')) . "@... [$displayts]"); ?> + ', clean($comment['comment']), ''; ?>]]> + + Modified: web/php-bugs/trunk/www/rss/search.php =================================================================== --- web/php-bugs/trunk/www/rss/search.php 2010-03-09 18:20:37 UTC (rev 296004) +++ web/php-bugs/trunk/www/rss/search.php 2010-03-09 19:00:00 UTC (rev 296005) @@ -39,7 +39,7 @@ xmlns:admin="http://webns.net/mvcb/" xmlns:content="http://purl.org/rss/1.0/modules/content/">'; echo "\n \n"; echo " {$siteBig} Bug Search Results\n"; -echo " http://{$site_url}{$basedir}/rss/search.php?" , htmlspecialchars(http_build_query($_GET)) , "\n"; +echo " http://{$site_url}{$basedir}/rss/search.php?" , clean(http_build_query($_GET)) , "\n"; echo " Search Results\n"; echo " en-us\n"; echo " {$site}-webmaster@lists.php.net\n"; @@ -64,26 +64,24 @@ } else { $desc .= substr($row['email'], 0, strpos($row['email'], '@')) . "@...\n"; } - $desc .= date(DATE_ATOM, $row['ts1a']) . "\n"; + $desc .= date(DATE_ATOM, $row['submitted']) . "\n"; $desc .= "PHP: {$row['php_version']}, OS: {$row['php_os']}, Package Version: {$row['package_version']}\n\n"; $desc .= $row['ldesc']; - $desc = '
' . utf8_encode(htmlspecialchars($desc)) . '
'; + $desc = '
' . clean($desc) . '
'; echo " \n"; $items .= " \n"; - $items .= ' ' . utf8_encode(htmlspecialchars("{$row['bug_type']} {$row['id']} [{$row['status']}] {$row['sdesc']}")) . "\n"; + $items .= ' ' . clean("{$row['bug_type']} {$row['id']} [{$row['status']}] {$row['sdesc']}") . "\n"; $items .= " http://{$site_url}{$basedir}/{$row['id']}\n"; $items .= ' \n"; $items .= ' \n"; if (!$row['unchanged']) { - $items .= ' ' . date(DATE_ATOM, $row['ts1a']) . "\n"; + $items .= ' ' . date(DATE_ATOM, $row['submitted']) . "\n"; } else { - $items .= ' ' . date(DATE_ATOM, $row['ts2a']) . "\n"; + $items .= ' ' . date(DATE_ATOM, $row['modified']) . "\n"; } - $items .= ' ' . utf8_encode(htmlspecialchars(spam_protect($row['email']))) . "\n"; - $items .= ' ' . - utf8_encode(htmlspecialchars($row['package_name'])) . ' ' . - utf8_encode(htmlspecialchars($row['bug_type'])) . "\n"; + $items .= ' ' . clean(spam_protect($row['email'])) . "\n"; + $items .= ' ' . clean($row['package_name']) . ' ' . clean($row['bug_type']) . "\n"; $items .= " \n"; } } else { @@ -110,7 +108,7 @@ echo "\n"; } Modified: web/php-bugs/trunk/www/rss/xml.php =================================================================== --- web/php-bugs/trunk/www/rss/xml.php 2010-03-09 18:20:37 UTC (rev 296004) +++ web/php-bugs/trunk/www/rss/xml.php 2010-03-09 19:00:00 UTC (rev 296005) @@ -1,13 +1,13 @@ \n"; foreach ($bug as $key => $value) { - echo " <$key>", utf8_encode(htmlspecialchars($value)), "\n"; + echo " <$key>", clean($value), "\n"; } foreach ($comments as $comment) { if (empty($comment['registered'])) continue; echo " \n"; foreach ($comment as $key => $value) { - echo " <$key>", utf8_encode(htmlspecialchars($value)), "\n"; + echo " <$key>", clean($value), "\n"; } echo " \n"; } Modified: web/php-bugs/trunk/www/search.php =================================================================== --- web/php-bugs/trunk/www/search.php 2010-03-09 18:20:37 UTC (rev 296004) +++ web/php-bugs/trunk/www/search.php 2010-03-09 19:00:00 UTC (rev 296005) @@ -15,17 +15,14 @@ // Authenticate (Disabled for now, searching does not require knowledge of user level) //bugs_authenticate($user, $pw, $logged_in, $is_trusted_developer); -$newrequest = $_REQUEST; -if (isset($newrequest['PHPSESSID'])) { - unset($newrequest['PHPSESSID']); -} +$newrequest = http_build_query(array_merge($_GET, $_POST)); if (!$count_only) { response_header( - 'Bugs :: Search', - " "); + 'Bugs :: Search', " + + + "); } // Include common query handler (used also by rss/search.php)