com web/master: Fix for SSH key foul-ups. Should finally close-out bug #61641.: manage/users.php
| From: | Daniel P. Brown | Date: | Wed, 16 May 2012 21:30:15 +0000 |
| Subject: | com web/master: Fix for SSH key foul-ups. Should finally close-out bug #61641.: manage/users.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-13542@lists.php.net to get a copy of this message | ||
Commit: 52ad51cd45f27bdb611d0e09391c36a69840b958
Author: Daniel P. Brown <danbrown@php.net> Wed, 16 May 2012 17:30:15 -0400
Parents: bc5cc4d1da2ce46c898ecabaa0205bf3f0f65416
Branches: master
Link: http://git.php.net/?p=web/master.git;a=commitdiff;h=52ad51cd45f27bdb611d0e09391c36a69840b958
Log:
Fix for SSH key foul-ups. Should finally close-out bug #61641.
Bugs:
https://bugs.php.net/61641
Changed paths:
M manage/users.php
Diff:
diff --git a/manage/users.php b/manage/users.php
index 75c5aa6..34be68f 100644
--- a/manage/users.php
+++ b/manage/users.php
@@ -171,7 +171,7 @@ if ($id && $in) {
. (!empty($in['passwd']) ? ",passwd='$in[passwd]'" :
"")
. (!empty($in['svnpasswd']) ?
",svnpasswd='$in[svnpasswd]'" : "")
. (!empty($in['md5passwd']) ?
",md5passwd='$in[md5passwd]'" : "")
- . (!empty($in['sshkey']) ? ",ssh_keys='$in[sshkey]'"
: ",ssh_keys=''")
+ . (!empty($in['sshkey']) ?
",ssh_keys='".escape(html_entity_decode($in[sshkey],ENT_QUOTES))."'" :
",ssh_keys=''")
. ((is_admin($user) && !empty($in['username'])) ?
",username='$in[username]'" : "")
. (is_admin($user) ? ",cvsaccess=$cvsaccess" : "")
. ",spamprotect=$spamprotect"
@@ -205,7 +205,7 @@ if ($id && $in) {
. (!empty($in['passwd']) ? ",passwd='$in[passwd]'" :
"")
. (!empty($in['svnpasswd']) ?
",svnpasswd='$in[svnpasswd]'" : "")
. (!empty($in['md5passwd']) ?
",md5passwd='$in[md5passwd]'" : "")
- . (!empty($in['sshkey']) ? ",ssh_keys='$in[sshkey]'" :
"")
+ . (!empty($in['sshkey']) ?
",ssh_keys='".escape(html_entity_decode($in[sshkey],ENT_QUOTES))."'" :
"")
. (is_admin($user) ? ",cvsaccess=$cvsaccess" : "")
. ",spamprotect=$spamprotect"
. ",use_sa=$use_sa"
@@ -314,7 +314,7 @@ table.useredit tr {
</tr>
<tr>
<th align="right">SSH Key</th>
- <td><textarea cols="50" rows="5"
name="in[sshkey]"><?php echo hscr($row['ssh_keys']) ?></textarea>
+ <td><textarea cols="50" rows="5"
name="in[sshkey]"><?php echo
escape(html_entity_decode($row['ssh_keys'],ENT_QUOTES)); ?></textarea>
<p>Adding/editing the SSH key takes a few minutes to propagate to the server.<br>
Multiple keys are allowed, separated using a newline.</p></td>
</tr>
@@ -476,7 +476,7 @@ function invalid_input($in) {
function is_admin($user) {
#TODO: use acls, once implemented.
- if
(in_array($user,array("jimw","rasmus","andrei","zeev","andi","sas","thies","rubys","ssb",
"wez", "philip", "davidc",
"helly","derick","bjori", "pajoye" ))) return true;
+ if
(in_array($user,array("jimw","rasmus","andrei","zeev","andi","sas","thies","rubys","ssb",
"wez", "philip", "davidc",
"helly","derick","bjori", "pajoye", "danbrown" )))
re
}
# returns false if $user is not allowed to modify $userid