cvs: php-bugs-web / bug.php report.php /include functions.inc
| From: | Jani Taskinen | Date: | Mon, 17 Feb 2003 10:01:55 +0000 |
| Subject: | cvs: php-bugs-web / bug.php report.php /include functions.inc | ||
| Groups: | php.mirrors | ||
| Request: | Send a blank email to php-mirrors+get-15752@lists.php.net to get a copy of this message | ||
sniper Mon Feb 17 05:01:55 2003 EDT
Modified files:
/php-bugs-web bug.php report.php
/php-bugs-web/include functions.inc
Log:
Made the emails addresses obfuscated..
Index: php-bugs-web/bug.php diff -u php-bugs-web/bug.php:1.51 php-bugs-web/bug.php:1.52 --- php-bugs-web/bug.php:1.51 Thu Feb 13 13:29:25 2003 +++ php-bugs-web/bug.php Mon Feb 17 05:01:54 2003 @@ -67,9 +67,15 @@ $errors[] = "You must provide a valid email address."; } + # Don't allow comments by the original report submitter + if (stripslashes($in['commentemail']) == $bug['email']) { + header("Location: $PHP_SELF?id=$id&edit=2"); + exit(); + } + # check that they aren't using a php.net mail address without # being authenticated (oh, the horror!) - if (preg_match('/^(.+)@php\.net/i', $in['commentemail'], $m)) { + if (preg_match('/^(.+)@php\.net/i', stripslashes($in['commentemail']), $m)) { if ($user != stripslashes($m[1]) || !verify_password($user,$pass)) { $errors[] = "You have to be logged in as a developer to use your php.net email address."; } @@ -111,18 +117,19 @@ } } + $from = ($bug[email] != $in[email] && !empty($in[email])) ? $in[email] : $bug[email]; + if (!$errors && !($errors = incoming_details_are_valid($in))) { /* update bug record */ - $query = "UPDATE bugdb SET sdesc='$in[sdesc]',status='$in[status]', bug_type='$in[bug_type]', php_version='$in[php_version]', php_os='$in[php_os]', ts2=NOW(), email='$in[email]' WHERE id=$id"; + $query = "UPDATE bugdb SET sdesc='$in[sdesc]',status='$in[status]', bug_type='$in[bug_type]', php_version='$in[php_version]', php_os='$in[php_os]', ts2=NOW(), email='$from' WHERE id=$id"; $success = @mysql_query($query); /* add comment */ if ($success && !empty($ncomment)) { - $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES ($id,'$in[email]',NOW(),'$ncomment')"; + $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES ($id,'$from',NOW(),'$ncomment')"; $success = @mysql_query($query); } } - $from = stripslashes($in['email']); } elseif ($in && $edit == 1) { if (!verify_password($user,stripslashes($pw))) { @@ -206,7 +213,7 @@ <?php }?> </tr> <tr id="submitter"> - <th>From:</th><td><?php echo htmlspecialchars($bug['email'])?></td> + <th>From:</th><td><?php echo htmlspecialchars(spam_protect($bug['email']))?></td> </tr> <tr id="categorization"> <th>Status:</th><td><?php echo htmlspecialchars($bug['status'])?></td> @@ -347,7 +354,7 @@ <tr> <th>Status:</th> <td><select name="in[status]"><?php show_state_options($in['status'],$edit,$bug['status'])?></select></td> -<?php if ($edit ==1) {?> +<?php if ($edit == 1) {?> <th>Assign to:</th> <td><input type="text" size="10" maxlength="16" name="in[assign]" value="<?php echo field('assign')?>" /></td> <?php }?> @@ -364,7 +371,11 @@ </tr> <tr> <th>From:</th> - <td colspan="5"><input type="text" size="40" maxlength="40" name="in[email]" value="<?php echo field('email')?>" /></td> + <td colspan="5"><?php echo spam_protect(field('email')); ?></td> + </tr> + <tr> + <th>New email:</th> + <td colspan="5"><input type="text" size="40" maxlength="40" name="in[email]" value="" /></td> </tr> <tr> <th>Version:</th> @@ -471,7 +482,7 @@ global $edit, $id, $trusted_developers, $user; echo "<div class=\"comment\">"; - echo "<b>[",format_date($ts),"] ", htmlspecialchars($email), "</b>\n"; + echo "<b>[",format_date($ts),"] ", htmlspecialchars(spam_protect($email)), "</b>\n"; echo ($edit == 1 && $com_id !== 0 && in_array($user, $trusted_developers)) ? "<a href=\"$PHP_SELF?id=$id&edit=1&delete_comment=$com_id\">[delete]</a>\n" : ''; echo "<pre class=\"note\">"; $note = addlinks(preg_replace("/(\r?\n){3,}/","\n\n",wordwrap($comment,72,"\n",1))); Index: php-bugs-web/report.php diff -u php-bugs-web/report.php:1.32 php-bugs-web/report.php:1.33 --- php-bugs-web/report.php:1.32 Sat Feb 8 10:21:11 2003 +++ php-bugs-web/report.php Mon Feb 17 05:01:54 2003 @@ -1,4 +1,5 @@ <?php /* vim: set noet ts=4 sw=4: : */ + require_once 'prepend.inc'; require_once 'cvs-auth.inc'; @@ -6,10 +7,10 @@ * them to continue */ if (isset($save) && isset($pw)) { # non-developers don't have $user set - setcookie("MAGIC_COOKIE",base64_encode("$user:$pw"),time()+3600*24*12,'/','.php.net'); + setcookie("MAGIC_COOKIE",base64_encode("$user:$pw"),time()+3600*24*12,'/','.php.net'); } if (isset($MAGIC_COOKIE) && !isset($user) && !isset($pw)) { - list($user,$pw) = explode(":", base64_decode($MAGIC_COOKIE)); + list($user,$pw) = explode(":", base64_decode($MAGIC_COOKIE)); } /* See bugs.sql for the table layout. */ @@ -17,12 +18,12 @@ $mail_bugs_to = "php-bugs@lists.php.net"; @mysql_pconnect("localhost","nobody","") - or die("Unable to connect to SQL server."); + or die("Unable to connect to SQL server."); @mysql_select_db("php3"); $errors = array(); if ($in) { - if (!($errors = incoming_details_are_valid($in,1))) { + if (!($errors = incoming_details_are_valid($_POST['in'], 1))) { if (!$in['did_luser_search']) { @@ -117,7 +118,7 @@ $cid = mysql_insert_id(); $report = ""; - $report .= "From: ".stripslashes($in['email'])."\n"; + $report .= "From: ".spam_protect(stripslashes($in['email']))."\n"; $report .= "Operating system: ".stripslashes($in['php_os'])."\n"; $report .= "PHP version: ".stripslashes($in['php_version'])."\n"; $report .= "PHP Bug Type: $in[bug_type]\n"; @@ -132,6 +133,7 @@ list($mailto,$mailfrom) = get_bugtype_mail($in['bug_type']); $email = stripslashes($in['email']); + $protected_email = '"'.spam_protect($email)."\" <$mailfrom>"; // provide shortcut URLS for "quick bug fixes" $dev_extra = ""; @@ -149,7 +151,7 @@ } // mail to appropriate mailing lists - if (mail($mailto, "#$cid [NEW]: $sdesc", $ascii_report."1\n-- \n$dev_extra", "From: $email\nX-PHP-Bug: $cid\nMessage-ID: <bug-$cid@bugs.php.net>")) { + if (mail($mailto, "#$cid [NEW]: $sdesc", $ascii_report."1\n-- \n$dev_extra", "From: $protected_email\nX-PHP-Bug: $cid\nMessage-ID: <bug-$cid@bugs.php.net>")) { // mail to reporter @mail($email, "Bug #$cid: $sdesc", $ascii_report."2\n", "From: PHP Bug Database <$mailfrom>\nX-PHP-Bug: $cid\nMessage-ID: <bug-$cid@bugs.php.net>"); Index: php-bugs-web/include/functions.inc diff -u php-bugs-web/include/functions.inc:1.63 php-bugs-web/include/functions.inc:1.64 --- php-bugs-web/include/functions.inc:1.63 Wed Jan 22 20:04:49 2003 +++ php-bugs-web/include/functions.inc Mon Feb 17 05:01:54 2003 @@ -1,10 +1,24 @@ <?php /* vim: set noet ts=4 sw=4 ft=php : */ +/* Email spam protection */ +function spam_protect($txt) +{ + $translate = array('@' => ' at ', '.' => ' dot '); + + /* php.net addresses are not protected! */ + if (preg_match('/^(.+)@php\.net/i', $txt)) { + return $txt; + } else { + return strtr($txt, $translate); + } +} + /* scrub user input so it can be re-output */ function clean($in) { return htmlspecialchars(get_magic_quotes_gpc()?stripslashes($in):$in); } + /* just rinse out any slashes. :) */ function rinse($in) { @@ -105,7 +119,7 @@ function show_version_options($current,$default="") { - $versions = array("4.3.0", "4.2.3", "4.2.2", "4.2.1", "4.2.0", "4CVS-".date("Y-m-d")." (stable)", "5CVS-".date("Y-m-d")." (dev)"); + $versions = array("4.3.1", "4.3.0", "4.2.3", "4CVS-".date("Y-m-d")." (stable)", "5CVS-".date("Y-m-d")." (dev)"); echo "<option value=\"\">--Please Select--</option>\n"; while (list(,$v) = each($versions)) { echo "<option", ($current == $v ? " selected" : ""), ">$v</option>\n"; @@ -179,6 +193,9 @@ $text = array(); $headers = array(); + /* Default addresses */ + list($mailto,$mailfrom) = get_bugtype_mail(oneof($in['bug_type'],$bug['bug_type'])); + /* Get rid of slashes in bug status */ $bug['status'] = stripslashes($bug['status']); @@ -201,20 +218,33 @@ switch ($edit) { case 3: - $headers[] = array(" Comment by", rinse($in['commentemail'])); + $from = spam_protect(rinse($in['commentemail'])); + $headers[] = array(" Comment by", $from); + $from = "\"$from\" <$mailfrom>"; break; case 2: - $headers[] = array(" User updated by", txfield('email')); + $from = spam_protect(txfield('email')); + $headers[] = array(" User updated by", $from); + $from = "\"$from\" <$mailfrom>"; break; default: $headers[] = array(" Updated by", $from); } - if (changed('sdesc')) + if (changed('sdesc')) { $headers[] = array("-Summary", $bug['sdesc']); + } + + $prefix = " "; + if (changed('email')) { + $headers[] = array("-Reported By", spam_protect($bug['email'])); + $prefix = "+"; + } + if ($f = spam_protect(txfield('email'))) { + $headers[] = array($prefix.'Reported By', $f); + } $fields = array( - 'email' => 'Reported By', 'status' => 'Status', 'bug_type' => 'Bug Type', 'php_os' => 'Operating System', @@ -252,9 +282,10 @@ $header_text .= str_pad($v[0] . ":", $maxlength) . " " . $hcontent . "\n"; } - if ($ncomment) + if ($ncomment) { $text[] = " New Comment:\n\n".stripslashes($ncomment); - + } + $text[] = get_old_comments($bug['id'], empty($ncomment)); /* format mail so it looks nice, use 72 to make piners happy */ @@ -273,8 +304,6 @@ "\n-- \nEdit this bug report at " . "http://bugs.php.net/?id=$bug[id]&edit=1\n"; - list($mailto,$mailfrom) = get_bugtype_mail(oneof($in['bug_type'],$bug['bug_type'])); - /* send mail if status was changed or there is a comment */ if ($in[status] != $bug[status] || $ncomment != "") { @@ -361,7 +390,7 @@ } while (($row = mysql_fetch_row($res)) && strlen($output) < $max_message_length && $count++ < $max_comments) { - $output .= "[$row[0]] $row[1]\n\n$row[2]\n\n$divider\n\n"; + $output .= "[$row[0]] ". spam_protect($row[1]) ."\n\n$row[2]\n\n$divider\n\n"; } if (strlen($output) < $max_message_length && $count < $max_comments) { @@ -369,7 +398,7 @@ if (!$res) return $output; $row = mysql_fetch_row($res); if (!$row) return $output; - return ("\n\nPrevious Comments:\n$divider\n\n" . $output . "[$row[0]] $row[1]\n\n$row[2]\n\n$divider\n\n"); + return ("\n\nPrevious Comments:\n$divider\n\n" . $output . "[$row[0]] ". spam_protect($row[1]) ."\n\n$row[2]\n\n$divider\n\n"); } else { return ("\n\nPrevious Comments:\n$divider\n\n" . $output . "The remainder of the comments for this report are too long. To view\nthe rest of the comments, please view the bug report online at\n http://bugs.php.net/$bug_id\n"); @@ -390,9 +419,13 @@ /* validate an incoming bug report */ function incoming_details_are_valid ($in, $initial=0) { + global $bug; + $errors = array(); - if (!preg_match("/[.\\w+-]+@[.\\w-]+\\.\\w{2,}/i",$in['email'])) { - $errors[] = "Please provide a valid email address."; + if ($initial || (!empty($in[email]) && $bug[email] != $in[email])) { + if (!preg_match("/[.\\w+-]+@[.\\w-]+\\.\\w{2,}/i",$in['email'])) { + $errors[] = "Please provide a valid email address."; + } } if ($in['bug_type'] == "none") {
Index: php-bugs-web/bug.php diff -u php-bugs-web/bug.php:1.51 php-bugs-web/bug.php:1.52 --- php-bugs-web/bug.php:1.51 Thu Feb 13 13:29:25 2003 +++ php-bugs-web/bug.php Mon Feb 17 05:01:54 2003 @@ -67,9 +67,15 @@ $errors[] = "You must provide a valid email address."; } + # Don't allow comments by the original report submitter + if (stripslashes($in['commentemail']) == $bug['email']) { + header("Location: $PHP_SELF?id=$id&edit=2"); + exit(); + } + # check that they aren't using a php.net mail address without # being authenticated (oh, the horror!) - if (preg_match('/^(.+)@php\.net/i', $in['commentemail'], $m)) { + if (preg_match('/^(.+)@php\.net/i', stripslashes($in['commentemail']), $m)) { if ($user != stripslashes($m[1]) || !verify_password($user,$pass)) { $errors[] = "You have to be logged in as a developer to use your php.net email address."; } @@ -111,18 +117,19 @@ } } + $from = ($bug[email] != $in[email] && !empty($in[email])) ? $in[email] : $bug[email]; + if (!$errors && !($errors = incoming_details_are_valid($in))) { /* update bug record */ - $query = "UPDATE bugdb SET sdesc='$in[sdesc]',status='$in[status]', bug_type='$in[bug_type]', php_version='$in[php_version]', php_os='$in[php_os]', ts2=NOW(), email='$in[email]' WHERE id=$id"; + $query = "UPDATE bugdb SET sdesc='$in[sdesc]',status='$in[status]', bug_type='$in[bug_type]', php_version='$in[php_version]', php_os='$in[php_os]', ts2=NOW(), email='$from' WHERE id=$id"; $success = @mysql_query($query); /* add comment */ if ($success && !empty($ncomment)) { - $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES ($id,'$in[email]',NOW(),'$ncomment')"; + $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES ($id,'$from',NOW(),'$ncomment')"; $success = @mysql_query($query); } } - $from = stripslashes($in['email']); } elseif ($in && $edit == 1) { if (!verify_password($user,stripslashes($pw))) { @@ -206,7 +213,7 @@ <?php }?> </tr> <tr id="submitter"> - <th>From:</th><td><?php echo htmlspecialchars($bug['email'])?></td> + <th>From:</th><td><?php echo htmlspecialchars(spam_protect($bug['email']))?></td> </tr> <tr id="categorization"> <th>Status:</th><td><?php echo htmlspecialchars($bug['status'])?></td> @@ -347,7 +354,7 @@ <tr> <th>Status:</th> <td><select name="in[status]"><?php show_state_options($in['status'],$edit,$bug['status'])?></select></td> -<?php if ($edit ==1) {?> +<?php if ($edit == 1) {?> <th>Assign to:</th> <td><input type="text" size="10" maxlength="16" name="in[assign]" value="<?php echo field('assign')?>" /></td> <?php }?> @@ -364,7 +371,11 @@ </tr> <tr> <th>From:</th> - <td colspan="5"><input type="text" size="40" maxlength="40" name="in[email]" value="<?php echo field('email')?>" /></td> + <td colspan="5"><?php echo spam_protect(field('email')); ?></td> + </tr> + <tr> + <th>New email:</th> + <td colspan="5"><input type="text" size="40" maxlength="40" name="in[email]" value="" /></td> </tr> <tr> <th>Version:</th> @@ -471,7 +482,7 @@ global $edit, $id, $trusted_developers, $user; echo "<div class=\"comment\">"; - echo "<b>[",format_date($ts),"] ", htmlspecialchars($email), "</b>\n"; + echo "<b>[",format_date($ts),"] ", htmlspecialchars(spam_protect($email)), "</b>\n"; echo ($edit == 1 && $com_id !== 0 && in_array($user, $trusted_developers)) ? "<a href=\"$PHP_SELF?id=$id&edit=1&delete_comment=$com_id\">[delete]</a>\n" : ''; echo "<pre class=\"note\">"; $note = addlinks(preg_replace("/(\r?\n){3,}/","\n\n",wordwrap($comment,72,"\n",1))); Index: php-bugs-web/report.php diff -u php-bugs-web/report.php:1.32 php-bugs-web/report.php:1.33 --- php-bugs-web/report.php:1.32 Sat Feb 8 10:21:11 2003 +++ php-bugs-web/report.php Mon Feb 17 05:01:54 2003 @@ -1,4 +1,5 @@ <?php /* vim: set noet ts=4 sw=4: : */ + require_once 'prepend.inc'; require_once 'cvs-auth.inc'; @@ -6,10 +7,10 @@ * them to continue */ if (isset($save) && isset($pw)) { # non-developers don't have $user set - setcookie("MAGIC_COOKIE",base64_encode("$user:$pw"),time()+3600*24*12,'/','.php.net'); + setcookie("MAGIC_COOKIE",base64_encode("$user:$pw"),time()+3600*24*12,'/','.php.net'); } if (isset($MAGIC_COOKIE) && !isset($user) && !isset($pw)) { - list($user,$pw) = explode(":", base64_decode($MAGIC_COOKIE)); + list($user,$pw) = explode(":", base64_decode($MAGIC_COOKIE)); } /* See bugs.sql for the table layout. */ @@ -17,12 +18,12 @@ $mail_bugs_to = "php-bugs@lists.php.net"; @mysql_pconnect("localhost","nobody","") - or die("Unable to connect to SQL server."); + or die("Unable to connect to SQL server."); @mysql_select_db("php3"); $errors = array(); if ($in) { - if (!($errors = incoming_details_are_valid($in,1))) { + if (!($errors = incoming_details_are_valid($_POST['in'], 1))) { if (!$in['did_luser_search']) { @@ -117,7 +118,7 @@ $cid = mysql_insert_id(); $report = ""; - $report .= "From: ".stripslashes($in['email'])."\n"; + $report .= "From: ".spam_protect(stripslashes($in['email']))."\n"; $report .= "Operating system: ".stripslashes($in['php_os'])."\n"; $report .= "PHP version: ".stripslashes($in['php_version'])."\n"; $report .= "PHP Bug Type: $in[bug_type]\n"; @@ -132,6 +133,7 @@ list($mailto,$mailfrom) = get_bugtype_mail($in['bug_type']); $email = stripslashes($in['email']); + $protected_email = '"'.spam_protect($email)."\" <$mailfrom>"; // provide shortcut URLS for "quick bug fixes" $dev_extra = ""; @@ -149,7 +151,7 @@ } // mail to appropriate mailing lists - if (mail($mailto, "#$cid [NEW]: $sdesc", $ascii_report."1\n-- \n$dev_extra", "From: $email\nX-PHP-Bug: $cid\nMessage-ID: <bug-$cid@bugs.php.net>")) { + if (mail($mailto, "#$cid [NEW]: $sdesc", $ascii_report."1\n-- \n$dev_extra", "From: $protected_email\nX-PHP-Bug: $cid\nMessage-ID: <bug-$cid@bugs.php.net>")) { // mail to reporter @mail($email, "Bug #$cid: $sdesc", $ascii_report."2\n", "From: PHP Bug Database <$mailfrom>\nX-PHP-Bug: $cid\nMessage-ID: <bug-$cid@bugs.php.net>"); Index: php-bugs-web/include/functions.inc diff -u php-bugs-web/include/functions.inc:1.63 php-bugs-web/include/functions.inc:1.64 --- php-bugs-web/include/functions.inc:1.63 Wed Jan 22 20:04:49 2003 +++ php-bugs-web/include/functions.inc Mon Feb 17 05:01:54 2003 @@ -1,10 +1,24 @@ <?php /* vim: set noet ts=4 sw=4 ft=php : */ +/* Email spam protection */ +function spam_protect($txt) +{ + $translate = array('@' => ' at ', '.' => ' dot '); + + /* php.net addresses are not protected! */ + if (preg_match('/^(.+)@php\.net/i', $txt)) { + return $txt; + } else { + return strtr($txt, $translate); + } +} + /* scrub user input so it can be re-output */ function clean($in) { return htmlspecialchars(get_magic_quotes_gpc()?stripslashes($in):$in); } + /* just rinse out any slashes. :) */ function rinse($in) { @@ -105,7 +119,7 @@ function show_version_options($current,$default="") { - $versions = array("4.3.0", "4.2.3", "4.2.2", "4.2.1", "4.2.0", "4CVS-".date("Y-m-d")." (stable)", "5CVS-".date("Y-m-d")." (dev)"); + $versions = array("4.3.1", "4.3.0", "4.2.3", "4CVS-".date("Y-m-d")." (stable)", "5CVS-".date("Y-m-d")." (dev)"); echo "<option value=\"\">--Please Select--</option>\n"; while (list(,$v) = each($versions)) { echo "<option", ($current == $v ? " selected" : ""), ">$v</option>\n"; @@ -179,6 +193,9 @@ $text = array(); $headers = array(); + /* Default addresses */ + list($mailto,$mailfrom) = get_bugtype_mail(oneof($in['bug_type'],$bug['bug_type'])); + /* Get rid of slashes in bug status */ $bug['status'] = stripslashes($bug['status']); @@ -201,20 +218,33 @@ switch ($edit) { case 3: - $headers[] = array(" Comment by", rinse($in['commentemail'])); + $from = spam_protect(rinse($in['commentemail'])); + $headers[] = array(" Comment by", $from); + $from = "\"$from\" <$mailfrom>"; break; case 2: - $headers[] = array(" User updated by", txfield('email')); + $from = spam_protect(txfield('email')); + $headers[] = array(" User updated by", $from); + $from = "\"$from\" <$mailfrom>"; break; default: $headers[] = array(" Updated by", $from); } - if (changed('sdesc')) + if (changed('sdesc')) { $headers[] = array("-Summary", $bug['sdesc']); + } + + $prefix = " "; + if (changed('email')) { + $headers[] = array("-Reported By", spam_protect($bug['email'])); + $prefix = "+"; + } + if ($f = spam_protect(txfield('email'))) { + $headers[] = array($prefix.'Reported By', $f); + } $fields = array( - 'email' => 'Reported By', 'status' => 'Status', 'bug_type' => 'Bug Type', 'php_os' => 'Operating System', @@ -252,9 +282,10 @@ $header_text .= str_pad($v[0] . ":", $maxlength) . " " . $hcontent . "\n"; } - if ($ncomment) + if ($ncomment) { $text[] = " New Comment:\n\n".stripslashes($ncomment); - + } + $text[] = get_old_comments($bug['id'], empty($ncomment)); /* format mail so it looks nice, use 72 to make piners happy */ @@ -273,8 +304,6 @@ "\n-- \nEdit this bug report at " . "http://bugs.php.net/?id=$bug[id]&edit=1\n"; - list($mailto,$mailfrom) = get_bugtype_mail(oneof($in['bug_type'],$bug['bug_type'])); - /* send mail if status was changed or there is a comment */ if ($in[status] != $bug[status] || $ncomment != "") { @@ -361,7 +390,7 @@ } while (($row = mysql_fetch_row($res)) && strlen($output) < $max_message_length && $count++ < $max_comments) { - $output .= "[$row[0]] $row[1]\n\n$row[2]\n\n$divider\n\n"; + $output .= "[$row[0]] ". spam_protect($row[1]) ."\n\n$row[2]\n\n$divider\n\n"; } if (strlen($output) < $max_message_length && $count < $max_comments) { @@ -369,7 +398,7 @@ if (!$res) return $output; $row = mysql_fetch_row($res); if (!$row) return $output; - return ("\n\nPrevious Comments:\n$divider\n\n" . $output . "[$row[0]] $row[1]\n\n$row[2]\n\n$divider\n\n"); + return ("\n\nPrevious Comments:\n$divider\n\n" . $output . "[$row[0]] ". spam_protect($row[1]) ."\n\n$row[2]\n\n$divider\n\n"); } else { return ("\n\nPrevious Comments:\n$divider\n\n" . $output . "The remainder of the comments for this report are too long. To view\nthe rest of the comments, please view the bug report online at\n http://bugs.php.net/$bug_id\n"); @@ -390,9 +419,13 @@ /* validate an incoming bug report */ function incoming_details_are_valid ($in, $initial=0) { + global $bug; + $errors = array(); - if (!preg_match("/[.\\w+-]+@[.\\w-]+\\.\\w{2,}/i",$in['email'])) { - $errors[] = "Please provide a valid email address."; + if ($initial || (!empty($in[email]) && $bug[email] != $in[email])) { + if (!preg_match("/[.\\w+-]+@[.\\w-]+\\.\\w{2,}/i",$in['email'])) { + $errors[] = "Please provide a valid email address."; + } } if ($in['bug_type'] == "none") {