com web/bugs: better fix for the issue, where private flag was lost after logging in as a security_developer: www/bug.php

From: Date: Tue, 08 May 2012 08:13:25 +0000
Subject: com web/bugs: better fix for the issue, where private flag was lost after logging in as a security_developer: www/bug.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-13477@lists.php.net to get a copy of this message
Commit: e76b079e552d0da3fde06a265f5b26225bd16855 Author: Ferenc Kovacs <tyra3l@gmail.com> Tue, 8 May 2012 10:13:25 +0200 Parents: aa24e30a1fe7392d2880e7f9225166fedb11c507 Branches: master Link: http://git.php.net/?p=web/bugs.git;a=commitdiff;h=e76b079e552d0da3fde06a265f5b26225bd16855 Log: better fix for the issue, where private flag was lost after logging in as a security_developer Changed paths: M www/bug.php Diff: diff --git a/www/bug.php b/www/bug.php index 5d37606..fe24674 100644 --- a/www/bug.php +++ b/www/bug.php @@ -158,8 +158,9 @@ if (!empty($_POST['in'])) { if ($user_flags & BUGS_DEV_USER) { $block_user = isset($_POST['in']['block_user_comment']) ? 'Y' : 'N'; } - if ($is_security_developer) { - $is_private = isset($_POST['in']['private']) ? 'Y': 'N'; + // security devs can change the private flag, if the field is set 'N' will make it private, everything else 'Y'. fail secure + if ($is_security_developer && isset($_POST['in']['private'])) { + $is_private = $_POST['in']['private'] == 'N' ? 'N': 'Y'; } } @@ -1013,7 +1014,6 @@ if (!$logged_in) { // Display original report if ($bug['ldesc']) { if (!$show_bug_info) { - echo '<input type="checkbox" name="in[private]" value="Y" '.($is_private == 'Y' ? 'checked="checked"' : '')..' /> '; echo 'This bug report is marked as private.'; } else if ($bug['status'] !== 'Spam') { output_note(0, $bug['submitted'], $bug['email'], $bug['ldesc'], 'comment', $bug['reporter_name'], false);

« previous php.webmaster (#13477) next »