Bug #54398 [Opn->Csd]: Cannot access security bugs as reporter

From: Date: Fri, 06 May 2011 20:25:16 +0000
Subject: Bug #54398 [Opn->Csd]: Cannot access security bugs as reporter
References: 1  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-10963@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=54398&edit=1 ID: 54398 Updated by: bjori@php.net Reported by: lekensteyn at gmail dot com Summary: Cannot access security bugs as reporter -Status: Open +Status: Closed Type: Bug Package: Website problem Operating System: Irrelevant PHP Version: Irrelevant -Assigned To: +Assigned To: bjori Block user comment: N Private report: N New Comment: The magic cookie was removed due to its insane security issues (ironically enough, by design). As for your bug report.. This seems to be fixed already. I filed an bug report with bugtype=security (http://bugs.php.net/bug.php? id=54679). Killing the session going and clicking 'edit' and priviting my password I can add additional comments and all the usual things.. If you can still reproduce this, please provide more details Previous Comments: ------------------------------------------------------------------------ [2011-03-26 22:00:32] lekensteyn at gmail dot com Thanks to Firebug, I injected the following form: --HTML-- <form action="patch-add.php?bug_id=[private_bug_id]" method="post"> <input type="password" name="pw" /> <input type="submit" /> </form> --HTML-- After entering the correct password and pressing submit, I get a form on which I can fill the patch details in. To submit it, I need to add a <input type="password" name="pw" /> field again. A bit hacky, but it works for me. Note: it should be fixed, why was this "magic cookie" removed? ------------------------------------------------------------------------ [2011-03-26 21:51:27] lekensteyn at gmail dot com Caused by commit 309587: First step in replacing the auth system... - kill MAGIC_COOKIE <--- argh! - update docweb to use the master api - update master to use a local session - set a IS_DEV cookie, to enable user note editing from phpweb - disabled full name retrieval from docweb http://svn.php.net/viewvc/web/php-bugs/trunk/include/functions.php?r1=309556&r2=309587&sortby=date ------------------------------------------------------------------------ [2011-03-26 21:41:35] lekensteyn at gmail dot com Description: ------------ I've recently reported a few security bugs via this bug tracking system. I have no php.net account, and use the password feature provided by the system. I can log in, but cannot post comments, nor can I add patches. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/bug.php?id=54398&edit=1

« previous php.webmaster (#10963) next »