com web/bugs: do the verify_bug_passwd() only once : www/bug.php

From: Date: Tue, 08 May 2012 23:16:24 +0000
Subject: com web/bugs: do the verify_bug_passwd() only once : www/bug.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-13495@lists.php.net to get a copy of this message
Commit: 12934ede3d12564185d2ae91fc54f92f57c5e133 Author: Ferenc Kovacs <tyra3l@gmail.com> Wed, 9 May 2012 01:16:24 +0200 Parents: c3cd0abeddbe527fa56b76dc3fa4b13325ab2d74 Branches: master Link: http://git.php.net/?p=web/bugs.git;a=commitdiff;h=12934ede3d12564185d2ae91fc54f92f57c5e133 Log: do the verify_bug_passwd() only once Changed paths: M www/bug.php Diff: diff --git a/www/bug.php b/www/bug.php index beb2fce..04da418 100644 --- a/www/bug.php +++ b/www/bug.php @@ -142,6 +142,10 @@ if (!$bug) { } $show_bug_info = bugs_has_access($bug_id, $bug, $pw, $user_flags); +if ($edit == 2 && !$show_bug_info && $pw && verify_bug_passwd($bug_id, bugs_get_hash($pw))) { + $show_bug_info = true; +} +var_dump($show_bug_info); if (isset($_POST['ncomment'])) { /* Bugs blocked to user comments can only be commented by the team */ @@ -248,11 +252,8 @@ if (isset($_POST['ncomment']) && !isset($_POST['preview']) && $edit == 3) { } elseif (isset($_POST['in']) && !isset($_POST['preview']) && $edit == 2) { // Edits submitted by original reporter for old bugs - if (!verify_bug_passwd($bug_id, bugs_get_hash($pw))) { + if (!$show_bug_info) { $errors[] = 'The password you supplied was incorrect.'; - } else { - // allow the original reporter to see the private report info - $show_bug_info = true; } // Bug is private (just should be available to trusted developers, original reporter and assigned dev) @@ -751,8 +752,7 @@ if ($edit == 1 || $edit == 2) { ?> <form id="update" action="bug.php?id=<?php echo $bug_id; ?>&amp;edit=<?php echo $edit; ?>" method="post"> <?php if ($edit == 2) { - if ($pw && verify_bug_passwd($bug['id'], bugs_get_hash($pw))) { - $show_bug_info = true; ?> + if ($show_bug_info) { ?> <div class="explain"> <table> <tr>

« previous php.webmaster (#13495) next »