Bug #60989 [PATCH]: logged in users can't access the security bugs reported by them

From: Date: Mon, 07 May 2012 20:59:27 +0000
Subject: Bug #60989 [PATCH]: logged in users can't access the security bugs reported by them
References: 1  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-13476@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60989&edit=1 ID: 60989 Patch added by: tyrael@php.net Reported by: tyrael@php.net Summary: logged in users can't access the security bugs reported by them Status: Assigned Type: Bug Package: Website problem PHP Version: Irrelevant Assigned To: tyrael Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: bugsweb-security.diff Revision: 1336424367 URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336424367 Previous Comments: ------------------------------------------------------------------------ [2012-05-06 19:08:38] tyrael@php.net Felipe reviewed the patch, he noticed two small mistakes (one line was commented out, instead of removed, and another issue was checking "$user_flags == BUGS_DEV_USER" instead of "$user_flags & BUGS_DEV_USER" I've updated the patch accordingly. ------------------------------------------------------------------------ [2012-05-06 19:03:31] tyrael@php.net The following patch has been added/updated: Patch Name: bugsweb-security.diff Revision: 1336331011 URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336331011 ------------------------------------------------------------------------ [2012-05-05 21:11:59] tyrael@php.net yeah, I'm fairly sure that I restricted the access correctly. I expanded the access only for one special case: if the bug reporter was logged in(hence he/she has an svn account), when reported the bug, he/she didn't get a password, so he/she won't be able to come back later and access the bug. I added an if clause to the bugs_has_access() function to check if the bug has the reporter_name field set, and the reporter equals to the currently logged in user's handle. so the current access list is the same as you mentioned, but the reporter can be either an anonymous user authenticated with the bug pw set when opening the bug, or an authenticated user. I also fixed that there will be no public info shown to unauthorized people. ------------------------------------------------------------------------ [2012-05-05 21:01:00] pajoye@php.net I'm not sure I understand all points you listed, however: Only security members (see the list in the bugs code) should be able to see a security report. anyone else should see nothing but the bug # and the text saying that this bug is private, but not the summary, title or any other information, not even the reporter name. This is what I discussed with Felipe earlier this week as well. ------------------------------------------------------------------------ [2012-05-05 20:28:40] tyrael@php.net The following patch has been added/updated: Patch Name: bugsweb-security.diff Revision: 1336249720 URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336249720 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=60989 -- Edit this bug report at https://bugs.php.net/bug.php?id=60989&edit=1

« previous php.webmaster (#13476) next »