cvs: php-master-web / forgot.php /entry cvs-account.php

From: Date: Tue, 16 Dec 2008 09:58:36 +0000
Subject: cvs: php-master-web / forgot.php /entry cvs-account.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-3334@lists.php.net to get a copy of this message
bjori Tue Dec 16 09:58:36 2008 UTC Modified files: /php-master-web/entry cvs-account.php /php-master-web forgot.php Log: Update to generate the svn pass too http://cvs.php.net/viewvc.cgi/php-master-web/entry/cvs-account.php?r1=1.18&r2=1.19&diff_format=u Index: php-master-web/entry/cvs-account.php diff -u php-master-web/entry/cvs-account.php:1.18 php-master-web/entry/cvs-account.php:1.19 --- php-master-web/entry/cvs-account.php:1.18 Wed Jun 11 21:41:21 2008 +++ php-master-web/entry/cvs-account.php Tue Dec 16 09:58:36 2008 @@ -1,6 +1,7 @@ <?php require 'email-validation.inc'; +require dirname(__FILE__) . '/../include/svn-auth.inc'; if (empty($name) || empty($email) || empty($username) || empty($passwd) || empty($note) || empty($group)) die("missing some parameters"); @@ -61,11 +62,13 @@ # TODO: fail if someone with that email address has an account. right now # this goes to the failto address since there's no password recovery # mechanism +$passwd = stripslashes($passwd); +$cvspasswd = crypt($passwd, substr(md5(time()), 0, 2)); +$md5passwd = md5($passwd); +$svnpasswd = gen_svn_pass($username, $passwd); -$passwd = crypt(stripslashes($passwd), substr(md5(time()), 0, 2)); - -$query = "INSERT INTO users (name,email,passwd,username) VALUES "; -$query .= "('$name','$email','$passwd','$username')"; +$query = "INSERT INTO users (name,email,passwd,svnpasswd,md5passwd,username) VALUES "; +$query .= "('$name','$email','$cvspasswd','$svnpasswd','$md5passwd','$username')"; //echo "<!--$query-->\n"; if (@mysql_query($query)) { @@ -95,7 +98,7 @@ "Full name: $name\n". "Email: $email\n". "ID: $username\n". - "Password: $passwd\n". + "Password: $cvspasswd\n". "Purpose: $note", "From: \"CVS Account Request\" <$email>"); } http://cvs.php.net/viewvc.cgi/php-master-web/forgot.php?r1=1.7&r2=1.8&diff_format=u Index: php-master-web/forgot.php diff -u php-master-web/forgot.php:1.7 php-master-web/forgot.php:1.8 --- php-master-web/forgot.php:1.7 Sun Jun 17 19:50:31 2007 +++ php-master-web/forgot.php Tue Dec 16 09:58:36 2008 @@ -1,5 +1,6 @@ -<?php +<?php // vim: et ts=2 sw=2 require 'functions.inc'; +require dirname(__FILE__) . "/include/svn-auth.inc"; function random_password() { $alphanum = array_merge(range("a","z"),range("A","Z"),range(0,9)); @@ -11,6 +12,12 @@ return $return; } +function username_from_forgotten($key, $id) { + $res = @mysql_query("SELECT username FROM users WHERE userid='$id' AND forgot='$key'"); + if ($res && ($row = mysql_fetch_array($res,MYSQL_ASSOC))) { + return $row["username"]; + } +} head("forgotten password"); mysql_connect("localhost","nobody","") @@ -21,8 +28,11 @@ if ($id && $key) { if ($n1 && $n2) { if ($n1 == $n2) { + $sn1 = stripslashes($n1); $passwd = addslashes(crypt(stripslashes($n1), substr(md5(time()), 0, 2))); - $res = @mysql_query("UPDATE users SET forgot=NULL,passwd='$passwd' WHERE userid='$id' AND forgot='$key'"); + $svnpasswd = gen_svn_pass(username_from_forgotten($key, $id), $sn1); + $md5passwd = md5($sn1); + $res = @mysql_query("UPDATE users SET forgot=NULL,passwd='$passwd',svnpasswd='$svnpasswd',md5passwd='$md5passwd' WHERE userid='$id' AND forgot='$key'"); if ($res && mysql_affected_rows()) { echo '<p>Okay, your password has been changed. It could take as long as an hour before this change makes it to the CVS server and other services. To change your password again, you\'ll have to start this process over to get a new key.</p>'; foot();

« previous php.webmaster (#3334) next »