cvs: php-master-web / forgot.php /entry cvs-account.php
| From: | Hannes Magnusson | Date: | Tue, 16 Dec 2008 09:58:36 +0000 |
| Subject: | cvs: php-master-web / forgot.php /entry cvs-account.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-3334@lists.php.net to get a copy of this message | ||
bjori Tue Dec 16 09:58:36 2008 UTC
Modified files:
/php-master-web/entry cvs-account.php
/php-master-web forgot.php
Log:
Update to generate the svn pass too
http://cvs.php.net/viewvc.cgi/php-master-web/entry/cvs-account.php?r1=1.18&r2=1.19&diff_format=u
Index: php-master-web/entry/cvs-account.php
diff -u php-master-web/entry/cvs-account.php:1.18 php-master-web/entry/cvs-account.php:1.19
--- php-master-web/entry/cvs-account.php:1.18 Wed Jun 11 21:41:21 2008
+++ php-master-web/entry/cvs-account.php Tue Dec 16 09:58:36 2008
@@ -1,6 +1,7 @@
<?php
require 'email-validation.inc';
+require dirname(__FILE__) . '/../include/svn-auth.inc';
if (empty($name) || empty($email) || empty($username) || empty($passwd) || empty($note) ||
empty($group))
die("missing some parameters");
@@ -61,11 +62,13 @@
# TODO: fail if someone with that email address has an account. right now
# this goes to the failto address since there's no password recovery
# mechanism
+$passwd = stripslashes($passwd);
+$cvspasswd = crypt($passwd, substr(md5(time()), 0, 2));
+$md5passwd = md5($passwd);
+$svnpasswd = gen_svn_pass($username, $passwd);
-$passwd = crypt(stripslashes($passwd), substr(md5(time()), 0, 2));
-
-$query = "INSERT INTO users (name,email,passwd,username) VALUES ";
-$query .=
"('$name','$email','$passwd','$username')";
+$query = "INSERT INTO users (name,email,passwd,svnpasswd,md5passwd,username) VALUES ";
+$query .=
"('$name','$email','$cvspasswd','$svnpasswd','$md5passwd','$username')";
//echo "<!--$query-->\n";
if (@mysql_query($query)) {
@@ -95,7 +98,7 @@
"Full name: $name\n".
"Email: $email\n".
"ID: $username\n".
- "Password: $passwd\n".
+ "Password: $cvspasswd\n".
"Purpose: $note",
"From: \"CVS Account Request\" <$email>");
}
http://cvs.php.net/viewvc.cgi/php-master-web/forgot.php?r1=1.7&r2=1.8&diff_format=u
Index: php-master-web/forgot.php
diff -u php-master-web/forgot.php:1.7 php-master-web/forgot.php:1.8
--- php-master-web/forgot.php:1.7 Sun Jun 17 19:50:31 2007
+++ php-master-web/forgot.php Tue Dec 16 09:58:36 2008
@@ -1,5 +1,6 @@
-<?php
+<?php // vim: et ts=2 sw=2
require 'functions.inc';
+require dirname(__FILE__) . "/include/svn-auth.inc";
function random_password() {
$alphanum =
array_merge(range("a","z"),range("A","Z"),range(0,9));
@@ -11,6 +12,12 @@
return $return;
}
+function username_from_forgotten($key, $id) {
+ $res = @mysql_query("SELECT username FROM users WHERE userid='$id' AND
forgot='$key'");
+ if ($res && ($row = mysql_fetch_array($res,MYSQL_ASSOC))) {
+ return $row["username"];
+ }
+}
head("forgotten password");
mysql_connect("localhost","nobody","")
@@ -21,8 +28,11 @@
if ($id && $key) {
if ($n1 && $n2) {
if ($n1 == $n2) {
+ $sn1 = stripslashes($n1);
$passwd = addslashes(crypt(stripslashes($n1), substr(md5(time()), 0, 2)));
- $res = @mysql_query("UPDATE users SET forgot=NULL,passwd='$passwd' WHERE
userid='$id' AND forgot='$key'");
+ $svnpasswd = gen_svn_pass(username_from_forgotten($key, $id), $sn1);
+ $md5passwd = md5($sn1);
+ $res = @mysql_query("UPDATE users SET
forgot=NULL,passwd='$passwd',svnpasswd='$svnpasswd',md5passwd='$md5passwd'
WHERE userid='$id' AND forgot='$key'");
if ($res && mysql_affected_rows()) {
echo '<p>Okay, your password has been changed. It could take as long as an hour
before this change makes it to the CVS server and other services. To change your password again,
you\'ll have to start this process over to get a new key.</p>';
foot();