Bug #60989 [Com]: logged in users can't access the security bugs reported by them

From: Date: Sat, 05 May 2012 21:11:59 +0000
Subject: Bug #60989 [Com]: logged in users can't access the security bugs reported by them
References: 1  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-13461@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60989&edit=1 ID: 60989 Comment by: tyrael@php.net Reported by: tyrael@php.net Summary: logged in users can't access the security bugs reported by them Status: Open Type: Bug Package: Website problem PHP Version: Irrelevant Block user comment: N Private report: N New Comment: yeah, I'm fairly sure that I restricted the access correctly. I expanded the access only for one special case: if the bug reporter was logged in(hence he/she has an svn account), when reported the bug, he/she didn't get a password, so he/she won't be able to come back later and access the bug. I added an if clause to the bugs_has_access() function to check if the bug has the reporter_name field set, and the reporter equals to the currently logged in user's handle. so the current access list is the same as you mentioned, but the reporter can be either an anonymous user authenticated with the bug pw set when opening the bug, or an authenticated user. I also fixed that there will be no public info shown to unauthorized people. Previous Comments: ------------------------------------------------------------------------ [2012-05-05 21:01:00] pajoye@php.net I'm not sure I understand all points you listed, however: Only security members (see the list in the bugs code) should be able to see a security report. anyone else should see nothing but the bug # and the text saying that this bug is private, but not the summary, title or any other information, not even the reporter name. This is what I discussed with Felipe earlier this week as well. ------------------------------------------------------------------------ [2012-05-05 20:28:40] tyrael@php.net The following patch has been added/updated: Patch Name: bugsweb-security.diff Revision: 1336249720 URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336249720 ------------------------------------------------------------------------ [2012-05-05 20:26:23] tyrael@php.net the attached patch should solve the issues. I tested it on my local developer environment and it seemed to work just fine, but given the recent events, I would like somebody to review it, before I push it. ------------------------------------------------------------------------ [2012-05-05 20:25:11] tyrael@php.net The following patch has been added/updated: Patch Name: bugsweb-security.diff Revision: 1336249511 URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336249511 ------------------------------------------------------------------------ [2012-05-05 18:35:52] tyrael@php.net so I would like to propose these changes: - logged in users should be able to access the private bugs reported by them. - only the reporter and the $security_developers should be able to see the quick summary of the private bugs. (summary, Submitted, Modified, From, Assigned, Status, Package, PHP version, OS, CVE-ID would be hidden or asterixed out) - the view tab should only contain the 'This bug report is marked as private.' message for non authorized people (non security dev nor reporter) - the developer tab for logged but non authorized people should only contain the 'This bug report is marked as private.' (currently it contains the 'This bug report is marked as private.' checkbox, 'Quick Fix' dropdown and the 'Block user comment' checkbox ) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=60989 -- Edit this bug report at https://bugs.php.net/bug.php?id=60989&edit=1

« previous php.webmaster (#13461) next »