Bug #60989 [Asn->Csd]: logged in users can't access the security bugs reported by them

From: Date: Tue, 08 May 2012 23:36:24 +0000
Subject: Bug #60989 [Asn->Csd]: logged in users can't access the security bugs reported by them
References: 1  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-13497@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60989&edit=1 ID: 60989 Updated by: tyrael@php.net Reported by: tyrael@php.net Summary: logged in users can't access the security bugs reported by them -Status: Assigned +Status: Closed Type: Bug Package: Website problem PHP Version: Irrelevant Assigned To: tyrael Block user comment: N Private report: N New Comment: This bug has been fixed in SVN. Since the websites are not directly updated from the SVN server, the fix might need some time to spread across the globe to all mirror sites, including PHP.net itself. Thank you for the report, and for helping us make PHP.net better. I commited the fixes in small chunks, plus I also discussed with johannes about his original fix, and come up with a better one. Previous Comments: ------------------------------------------------------------------------ [2012-05-07 20:59:27] tyrael@php.net The following patch has been added/updated: Patch Name: bugsweb-security.diff Revision: 1336424367 URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336424367 ------------------------------------------------------------------------ [2012-05-06 19:08:38] tyrael@php.net Felipe reviewed the patch, he noticed two small mistakes (one line was commented out, instead of removed, and another issue was checking "$user_flags == BUGS_DEV_USER" instead of "$user_flags & BUGS_DEV_USER" I've updated the patch accordingly. ------------------------------------------------------------------------ [2012-05-06 19:03:31] tyrael@php.net The following patch has been added/updated: Patch Name: bugsweb-security.diff Revision: 1336331011 URL: https://bugs.php.net/patch-display.php?bug=60989&patch=bugsweb-security.diff&revision=1336331011 ------------------------------------------------------------------------ [2012-05-05 21:11:59] tyrael@php.net yeah, I'm fairly sure that I restricted the access correctly. I expanded the access only for one special case: if the bug reporter was logged in(hence he/she has an svn account), when reported the bug, he/she didn't get a password, so he/she won't be able to come back later and access the bug. I added an if clause to the bugs_has_access() function to check if the bug has the reporter_name field set, and the reporter equals to the currently logged in user's handle. so the current access list is the same as you mentioned, but the reporter can be either an anonymous user authenticated with the bug pw set when opening the bug, or an authenticated user. I also fixed that there will be no public info shown to unauthorized people. ------------------------------------------------------------------------ [2012-05-05 21:01:00] pajoye@php.net I'm not sure I understand all points you listed, however: Only security members (see the list in the bugs code) should be able to see a security report. anyone else should see nothing but the bug # and the text saying that this bug is private, but not the summary, title or any other information, not even the reporter name. This is what I discussed with Felipe earlier this week as well. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=60989 -- Edit this bug report at https://bugs.php.net/bug.php?id=60989&edit=1

« previous php.webmaster (#13497) next »