Bug #54398 [Opn->Csd]: Cannot access security bugs as reporter
| From: | bjori@php.net | Date: | Fri, 06 May 2011 20:25:16 +0000 |
| Subject: | Bug #54398 [Opn->Csd]: Cannot access security bugs as reporter | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-10963@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=54398&edit=1
ID: 54398
Updated by: bjori@php.net
Reported by: lekensteyn at gmail dot com
Summary: Cannot access security bugs as reporter
-Status: Open
+Status: Closed
Type: Bug
Package: Website problem
Operating System: Irrelevant
PHP Version: Irrelevant
-Assigned To:
+Assigned To: bjori
Block user comment: N
Private report: N
New Comment:
The magic cookie was removed due to its insane security issues
(ironically
enough,
by design).
As for your bug report.. This seems to be fixed already.
I filed an bug report with bugtype=security
(http://bugs.php.net/bug.php?
id=54679).
Killing the session going and clicking 'edit' and priviting my password
I can
add
additional comments and all the usual things..
If you can still reproduce this, please provide more details
Previous Comments:
------------------------------------------------------------------------
[2011-03-26 22:00:32] lekensteyn at gmail dot com
Thanks to Firebug, I injected the following form:
--HTML--
<form action="patch-add.php?bug_id=[private_bug_id]" method="post">
<input type="password" name="pw" />
<input type="submit" />
</form>
--HTML--
After entering the correct password and pressing submit, I get a form on
which I can fill the patch details in.
To submit it, I need to add a <input type="password" name="pw" /> field
again.
A bit hacky, but it works for me. Note: it should be fixed, why was this
"magic cookie" removed?
------------------------------------------------------------------------
[2011-03-26 21:51:27] lekensteyn at gmail dot com
Caused by commit 309587:
First step in replacing the auth system...
- kill MAGIC_COOKIE <--- argh!
- update docweb to use the master api
- update master to use a local session
- set a IS_DEV cookie, to enable user note editing from phpweb
- disabled full name retrieval from docweb
http://svn.php.net/viewvc/web/php-bugs/trunk/include/functions.php?r1=309556&r2=309587&sortby=date
------------------------------------------------------------------------
[2011-03-26 21:41:35] lekensteyn at gmail dot com
Description:
------------
I've recently reported a few security bugs via this bug tracking system.
I have no php.net account, and use the password feature provided by the
system.
I can log in, but cannot post comments, nor can I add patches.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=54398&edit=1