com web/master: Fix for SSH key foul-ups. Should finally close-out bug #61641.: manage/users.php

From: Date: Wed, 16 May 2012 21:30:15 +0000
Subject: com web/master: Fix for SSH key foul-ups. Should finally close-out bug #61641.: manage/users.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-13542@lists.php.net to get a copy of this message
Commit: 52ad51cd45f27bdb611d0e09391c36a69840b958 Author: Daniel P. Brown <danbrown@php.net> Wed, 16 May 2012 17:30:15 -0400 Parents: bc5cc4d1da2ce46c898ecabaa0205bf3f0f65416 Branches: master Link: http://git.php.net/?p=web/master.git;a=commitdiff;h=52ad51cd45f27bdb611d0e09391c36a69840b958 Log: Fix for SSH key foul-ups. Should finally close-out bug #61641. Bugs: https://bugs.php.net/61641 Changed paths: M manage/users.php Diff: diff --git a/manage/users.php b/manage/users.php index 75c5aa6..34be68f 100644 --- a/manage/users.php +++ b/manage/users.php @@ -171,7 +171,7 @@ if ($id && $in) { . (!empty($in['passwd']) ? ",passwd='$in[passwd]'" : "") . (!empty($in['svnpasswd']) ? ",svnpasswd='$in[svnpasswd]'" : "") . (!empty($in['md5passwd']) ? ",md5passwd='$in[md5passwd]'" : "") - . (!empty($in['sshkey']) ? ",ssh_keys='$in[sshkey]'" : ",ssh_keys=''") + . (!empty($in['sshkey']) ? ",ssh_keys='".escape(html_entity_decode($in[sshkey],ENT_QUOTES))."'" : ",ssh_keys=''") . ((is_admin($user) && !empty($in['username'])) ? ",username='$in[username]'" : "") . (is_admin($user) ? ",cvsaccess=$cvsaccess" : "") . ",spamprotect=$spamprotect" @@ -205,7 +205,7 @@ if ($id && $in) { . (!empty($in['passwd']) ? ",passwd='$in[passwd]'" : "") . (!empty($in['svnpasswd']) ? ",svnpasswd='$in[svnpasswd]'" : "") . (!empty($in['md5passwd']) ? ",md5passwd='$in[md5passwd]'" : "") - . (!empty($in['sshkey']) ? ",ssh_keys='$in[sshkey]'" : "") + . (!empty($in['sshkey']) ? ",ssh_keys='".escape(html_entity_decode($in[sshkey],ENT_QUOTES))."'" : "") . (is_admin($user) ? ",cvsaccess=$cvsaccess" : "") . ",spamprotect=$spamprotect" . ",use_sa=$use_sa" @@ -314,7 +314,7 @@ table.useredit tr { </tr> <tr> <th align="right">SSH Key</th> - <td><textarea cols="50" rows="5" name="in[sshkey]"><?php echo hscr($row['ssh_keys']) ?></textarea> + <td><textarea cols="50" rows="5" name="in[sshkey]"><?php echo escape(html_entity_decode($row['ssh_keys'],ENT_QUOTES)); ?></textarea> <p>Adding/editing the SSH key takes a few minutes to propagate to the server.<br> Multiple keys are allowed, separated using a newline.</p></td> </tr> @@ -476,7 +476,7 @@ function invalid_input($in) { function is_admin($user) { #TODO: use acls, once implemented. - if (in_array($user,array("jimw","rasmus","andrei","zeev","andi","sas","thies","rubys","ssb", "wez", "philip", "davidc", "helly","derick","bjori", "pajoye" ))) return true; + if (in_array($user,array("jimw","rasmus","andrei","zeev","andi","sas","thies","rubys","ssb", "wez", "philip", "davidc", "helly","derick","bjori", "pajoye", "danbrown" ))) re } # returns false if $user is not allowed to modify $userid

« previous php.webmaster (#13542) next »