Modified: web/php-bugs/trunk/include/functions.php =================================================================== --- web/php-bugs/trunk/include/functions.php 2010-11-15 18:48:48 UTC (rev 305381) +++ web/php-bugs/trunk/include/functions.php 2010-11-15 20:22:55 UTC (rev 305382) @@ -727,7 +727,9 @@ 'php_os' => 'Operating System', 'php_version' => 'PHP Version', 'assign' => 'Assigned To', - 'block_user_comment' => 'Block user comment' + 'block_user_comment' => 'Block user comment', + 'private' => 'Private report', + 'cve_id' => 'CVE-ID' ); foreach (array_keys($fields) as $name) { @@ -754,7 +756,9 @@ 'php_os' => 'Operating System', 'php_version' => 'PHP Version', 'assign' => 'Assigned To', - 'block_user_comment' => 'Block user comment' + 'block_user_comment' => 'Block user comment', + 'private' => 'Private report', + 'cve_id' => 'CVE-ID' ); // make diff output aligned @@ -830,7 +834,9 @@ 'php_os' => 'Operating System', 'php_version' => 'PHP Version', 'assign' => 'Assigned To', - 'block_user_comment' => 'Block user comment' + 'block_user_comment' => 'Block user comment', + 'private' => 'Private report', + 'cve_id' => 'CVE-ID', ); foreach ($fields as $name => $desc) { Modified: web/php-bugs/trunk/include/query.php =================================================================== --- web/php-bugs/trunk/include/query.php 2010-11-15 18:48:48 UTC (rev 305381) +++ web/php-bugs/trunk/include/query.php 2010-11-15 20:22:55 UTC (rev 305382) @@ -31,6 +31,7 @@ $php_os = !empty($_GET['php_os']) ? $_GET['php_os'] : ''; $php_os_not = !empty($_GET['php_os_not']) ? 'not' : ''; $phpver = !empty($_GET['phpver']) ? $_GET['phpver'] : ''; +$cve_id = !empty($_GET['cve_id']) ? $_GET['cve_id'] : ''; $patch = !empty($_GET['patch']) ? $_GET['patch'] : ''; $begin = (int) (!empty($_GET['begin']) ? $_GET['begin'] : 0); $limit = (defined('MAX_BUGS_RETURN')) ? MAX_BUGS_RETURN : 30; @@ -59,8 +60,13 @@ if (in_array($order_by, array('votes_count', 'avg_score'))) { $query .= 'LEFT JOIN bugdb_votes v ON bugdb.id = v.bug'; } - + $where_clause = ' WHERE 1 = 1 '; + + if (!$is_trusted_developer) { + /* Non trusted developer should see the Security related bug report just when it is public */ + $where_clause .= ' AND (bugdb.package_name <> "Security related" OR private = "N") '; + } if (!empty($package_name)) { $where_clause .= ' AND bugdb.package_name'; @@ -153,6 +159,10 @@ $where_clause .= " AND bugdb.php_version LIKE '" . $dbh->escape($phpver) . "%'"; } + if ($cve_id != '') { + $where_clause .= " AND bugdb.cve_id LIKE '" . $dbh->escape($cve_id) . "%'"; + } + if ($patch != '') { $where_clause .= " AND EXISTS (SELECT 1 FROM bugdb_patchtracker WHERE bugdb_id = bugdb.id LIMIT 1)"; } Modified: web/php-bugs/trunk/include/trusted-devs.php =================================================================== --- web/php-bugs/trunk/include/trusted-devs.php 2010-11-15 18:48:48 UTC (rev 305381) +++ web/php-bugs/trunk/include/trusted-devs.php 2010-11-15 20:22:55 UTC (rev 305382) @@ -11,4 +11,5 @@ 'bjori', 'rasmus', 'philip', + 'felipe' ); Modified: web/php-bugs/trunk/sql/bugs.sql =================================================================== --- web/php-bugs/trunk/sql/bugs.sql 2010-11-15 18:48:48 UTC (rev 305381) +++ web/php-bugs/trunk/sql/bugs.sql 2010-11-15 20:22:55 UTC (rev 305382) @@ -20,6 +20,8 @@ passwd varchar(20) default NULL, registered tinyint(1) NOT NULL default '0', block_user_comment char(1) default 'N', + cve_id varchar(15) default NULL, + private char(1) default 'N', PRIMARY KEY (id), KEY php_version (php_version(1)), KEY status (status), Modified: web/php-bugs/trunk/www/bug.php =================================================================== --- web/php-bugs/trunk/www/bug.php 2010-11-15 18:48:48 UTC (rev 305381) +++ web/php-bugs/trunk/www/bug.php 2010-11-15 20:22:55 UTC (rev 305382) @@ -138,6 +138,13 @@ exit; } +$show_bug_info = ($bug['private'] == 'Y' ? false : true); + +// Just the reporter and trusted developer should see the private report info +if ($bug['private'] == 'Y' && $edit == 1 && $is_trusted_developer) { + $show_bug_info = true; +} + if (isset($_POST['ncomment'])) { /* Bugs blocked to user comments can only be commented by the team */ if ($bug['block_user_comment'] == 'Y' && !($is_trusted_developer || (isset($logged_in) && $logged_in == 'developer'))) { @@ -150,6 +157,7 @@ } } $block_user = (!empty($_POST['in']) && isset($_POST['in']['block_user_comment'])) ? $_POST['in']['block_user_comment'] : $bug['block_user_comment']; +$is_private = (!empty($_POST['in']) && isset($_POST['in']['private'])) ? $_POST['in']['private'] : $bug['private']; // Handle any updates, displaying errors if there were any $RESOLVE_REASONS = $FIX_VARIATIONS = $pseudo_pkgs = array(); @@ -167,6 +175,14 @@ if (isset($_POST['ncomment']) && !isset($_POST['preview']) && $edit == 3) { // Submission of additional comment by others + // Bug is private (just should be available to trusted developers and to reporter) + if (!$is_trusted_developer && $bug['private'] == 'Y') { + response_header('Private report'); + display_bug_error("The bug #{$bug_id} is not available to public, if you are the original reporter use the Edit tab"); + response_footer(); + exit; + } + // Check if session answer is set, then compare it with the post captcha value. // If it's not the same, then it's an incorrect password. if (!$logged_in) { @@ -221,10 +237,29 @@ } elseif (isset($_POST['in']) && !isset($_POST['preview']) && $edit == 2) { // Edits submitted by original reporter for old bugs - + if (!verify_bug_passwd($bug_id, $pw)) { $errors[] = 'The password you supplied was incorrect.'; + } else { + // allow the original reporter to see the private report info + $show_bug_info = true; } + + // Bug is private (just should be available to trusted developers and to original reporter) + if (!$show_bug_info && $bug['private'] == 'Y') { + response_header('Private report'); + display_bug_error("The bug #{$bug_id} is not available to public"); + response_footer(); + exit; + } + + // Just trusted dev can change the package name of a Security related bug to another package + if ($bug['private'] == 'Y' && !$is_trusted_developer + && $bug['package_name'] == 'Security related' + && $_POST['in']['package_name'] != $bug['package_name']) { + + $errors[] = 'You cannot change the package of a Security related bug!'; + } $ncomment = trim($_POST['ncomment']); if (!$ncomment) { @@ -258,6 +293,16 @@ } if (!$errors && !($errors = incoming_details_are_valid($_POST['in'], false))) { + // Allow the reporter to change the package to 'Security related', hence mark + // the report as private + if ($bug['private'] == 'N' && $_POST['in']['package_name'] == 'Security related' + && $_POST['in']['package_name'] != $bug['package_name']) { + + $is_private = $_POST['in']['private'] = 'Y'; + } else { + $is_private = $bug['private']; + } + $dbh->prepare(" UPDATE bugdb SET @@ -268,7 +313,8 @@ php_version = ?, php_os = ?, email = ?, - ts2 = NOW() + ts2 = NOW(), + private = ? WHERE id={$bug_id} ")->execute(array( $_POST['in']['sdesc'], @@ -278,6 +324,7 @@ $_POST['in']['php_version'], $_POST['in']['php_os'], $from, + $is_private )); // Add changelog entry @@ -306,6 +353,15 @@ } elseif (isset($_POST['in']) && is_array($_POST['in']) && !isset($_POST['preview']) && $edit == 1) { // Edits submitted by developer + + // Bug is private (just should be available to trusted developers and to reporter) + if (!$is_trusted_developer && $bug['private'] == 'Y') { + response_header('Private report'); + display_bug_error("The bug #{$bug_id} is not available to public"); + response_footer(); + exit; + } + if ($logged_in != 'developer') { $errors[] = 'You have to login first in order to edit the bug report.'; } @@ -391,6 +447,15 @@ { $query .= " email='{$_POST['in']['email']}',"; } + + // Changing the package to 'Security related' should mark the bug as private automatically + if ($bug['package_name'] != $_POST['in']['package_name']) { + if ($_POST['in']['package_name'] == 'Security related') { + $is_private = $_POST['in']['private'] = 'Y'; + } else { + $is_private = $_POST['in']['private'] = 'N'; + } + } if ($logged_in != 'developer') { // don't reset assigned status @@ -418,6 +483,8 @@ php_version = ?, php_os = ?, block_user_comment = ?, + cve_id = ?, + private = ?, ts2 = NOW() WHERE id = {$bug_id} ")->execute(array ( @@ -428,7 +495,9 @@ $_POST['in']['assign'], $_POST['in']['php_version'], $_POST['in']['php_os'], - $_POST['in']['block_user_comment'] + $_POST['in']['block_user_comment'], + $_POST['in']['cve_id'], + $_POST['in']['private'] )); // Add changelog entry @@ -535,7 +604,7 @@
| OS: | + + | ||
|---|---|---|---|
| Private report: | ++ | CVE-ID: | ++ |