Re: Strange account activation problem

From: Date: Mon, 10 Aug 2009 10:38:43 +0000
Subject: Re: Strange account activation problem
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-52601@lists.php.net to get a copy of this message
Hi, Daniel O'Connor wrote:
I had a brief look at pearweb code, there are some obvious problems. First, confirmation of account on bug page is checked via a flag in bugdb table, while it is checked via absence of record in bug_account_request table on resend-request page.
Next, the biggest problem is related to pearweb using The Most Popular Open Source Database: My$QL doesn't allow having fulltext index on a transactional table, so bugdb table has no constraints and / or foreign keys. Therefore confirmRequest() method is extremely fragile, with a large amount of updates outside a transaction block and without any constraint checking. Also there is that strange PEAR_Bug_Accountrequest::cleanOldRequests() method that probably does not work as expected, since the unconfirmed bug linked above is still here.
Oh god my eyes. It does work in the constructor.
Yeah, it does *work* but probably doesn't work *as expected*... I have a feeling that a record is deleted from bug_account_request somehow, but all the other stuff is left intact, and thus a person can never confirm it afterwards. BTW, can someone having access to an actual DB test this hypothesis?
*shivver* I'm a bit scared of charging around and refactoring that because its huge, and there is no test coverage.
Yep, touching it without test coverage is a no-no.
Alexey, I don't suppose you'd mind generating a bunch of small (obvious) test cases which break it / adding bug reports for them/throwing them into svn?
OK, seems I'll finally have to defile my computer by installing a dolphin-shaped abomination that is MySQL... I'll see what I can do once I understand how the current test suite for pearweb is organized.

« previous php.pear.dev (#52601) next »