Bug #60989 [PATCH]: logged in users can't access the security bugs reported by them
| From: | tyrael@php.net | Date: | Mon, 07 May 2012 20:59:27 +0000 |
| Subject: | Bug #60989 [PATCH]: logged in users can't access the security bugs reported by them | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-13476@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60989&edit=1
ID: 60989
Patch added by: tyrael@php.net
Reported by: tyrael@php.net
Summary: logged in users can't access the security bugs
reported by them
Status: Assigned
Type: Bug
Package: Website problem
PHP Version: Irrelevant
Assigned To: tyrael
Block user comment: N
Private report: N
New Comment:
The following patch has been added/updated:
Patch Name: bugsweb-security.diff
Revision: 1336424367
URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336424367
Previous Comments:
------------------------------------------------------------------------
[2012-05-06 19:08:38] tyrael@php.net
Felipe reviewed the patch, he noticed two small mistakes (one line was commented
out, instead of removed, and another issue was checking "$user_flags ==
BUGS_DEV_USER" instead of "$user_flags & BUGS_DEV_USER"
I've updated the patch accordingly.
------------------------------------------------------------------------
[2012-05-06 19:03:31] tyrael@php.net
The following patch has been added/updated:
Patch Name: bugsweb-security.diff
Revision: 1336331011
URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336331011
------------------------------------------------------------------------
[2012-05-05 21:11:59] tyrael@php.net
yeah, I'm fairly sure that I restricted the access correctly.
I expanded the access only for one special case: if the bug reporter was logged
in(hence he/she has an svn account), when reported the bug, he/she didn't get a
password, so he/she won't be able to come back later and access the bug.
I added an if clause to the bugs_has_access() function to check if the bug has
the reporter_name field set, and the reporter equals to the currently logged in
user's handle.
so the current access list is the same as you mentioned, but the reporter can be
either an anonymous user authenticated with the bug pw set when opening the bug,
or an authenticated user.
I also fixed that there will be no public info shown to unauthorized people.
------------------------------------------------------------------------
[2012-05-05 21:01:00] pajoye@php.net
I'm not sure I understand all points you listed, however:
Only security members (see the list in the bugs code) should be able to see a
security report.
anyone else should see nothing but the bug # and the text saying that this bug
is private, but not the summary, title or any other information, not even the
reporter name.
This is what I discussed with Felipe earlier this week as well.
------------------------------------------------------------------------
[2012-05-05 20:28:40] tyrael@php.net
The following patch has been added/updated:
Patch Name: bugsweb-security.diff
Revision: 1336249720
URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336249720
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60989
--
Edit this bug report at https://bugs.php.net/bug.php?id=60989&edit=1