com web/bugs: do the verify_bug_passwd() only once : www/bug.php
| From: | Ferenc Kovacs | Date: | Tue, 08 May 2012 23:16:24 +0000 |
| Subject: | com web/bugs: do the verify_bug_passwd() only once : www/bug.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-13495@lists.php.net to get a copy of this message | ||
Commit: 12934ede3d12564185d2ae91fc54f92f57c5e133
Author: Ferenc Kovacs <tyra3l@gmail.com> Wed, 9 May 2012 01:16:24 +0200
Parents: c3cd0abeddbe527fa56b76dc3fa4b13325ab2d74
Branches: master
Link: http://git.php.net/?p=web/bugs.git;a=commitdiff;h=12934ede3d12564185d2ae91fc54f92f57c5e133
Log:
do the verify_bug_passwd() only once
Changed paths:
M www/bug.php
Diff:
diff --git a/www/bug.php b/www/bug.php
index beb2fce..04da418 100644
--- a/www/bug.php
+++ b/www/bug.php
@@ -142,6 +142,10 @@ if (!$bug) {
}
$show_bug_info = bugs_has_access($bug_id, $bug, $pw, $user_flags);
+if ($edit == 2 && !$show_bug_info && $pw && verify_bug_passwd($bug_id,
bugs_get_hash($pw))) {
+ $show_bug_info = true;
+}
+var_dump($show_bug_info);
if (isset($_POST['ncomment'])) {
/* Bugs blocked to user comments can only be commented by the team */
@@ -248,11 +252,8 @@ if (isset($_POST['ncomment']) &&
!isset($_POST['preview']) && $edit == 3) {
} elseif (isset($_POST['in']) && !isset($_POST['preview']) &&
$edit == 2) {
// Edits submitted by original reporter for old bugs
- if (!verify_bug_passwd($bug_id, bugs_get_hash($pw))) {
+ if (!$show_bug_info) {
$errors[] = 'The password you supplied was incorrect.';
- } else {
- // allow the original reporter to see the private report info
- $show_bug_info = true;
}
// Bug is private (just should be available to trusted developers, original reporter and assigned
dev)
@@ -751,8 +752,7 @@ if ($edit == 1 || $edit == 2) { ?>
<form id="update" action="bug.php?id=<?php echo $bug_id;
?>&edit=<?php echo $edit; ?>" method="post">
<?php if ($edit == 2) {
- if ($pw && verify_bug_passwd($bug['id'], bugs_get_hash($pw))) {
- $show_bug_info = true; ?>
+ if ($show_bug_info) { ?>
<div class="explain">
<table>
<tr>