svn: /web/php-master/trunk/entry/ cvs-account.php svn-account.php

From: Date: Wed, 29 Jul 2009 14:40:12 +0000
Subject: svn: /web/php-master/trunk/entry/ cvs-account.php svn-account.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-5550@lists.php.net to get a copy of this message
philip Wed, 29 Jul 2009 14:40:12 +0000 Revision: http://svn.php.net/viewvc?view=revision&revision=286511 Log: Renamed cvs-account.php to svn-account.php as svn-php.php refers to the latter currently. peclweb will be updated later. Changed paths: D web/php-master/trunk/entry/cvs-account.php A + web/php-master/trunk/entry/svn-account.php (from web/php-master/trunk/entry/cvs-account.php:r286510) Deleted: web/php-master/trunk/entry/cvs-account.php =================================================================== --- web/php-master/trunk/entry/cvs-account.php 2009-07-29 14:27:43 UTC (rev 286510) +++ web/php-master/trunk/entry/cvs-account.php 2009-07-29 14:40:12 UTC (rev 286511) @@ -1,104 +0,0 @@ -<?php - -require 'email-validation.inc'; -require dirname(__FILE__) . '/../include/svn-auth.inc'; - -if (empty($name) || empty($email) || empty($username) || empty($passwd) || empty($note) || empty($group)) - die("missing some parameters"); - -// Sophisticated security/spam protection question -if (empty($yesno) || $yesno != "yes") { - die("You did not fill the form out correctly"); -} - -switch($group) { -case "php": - $mailto = 'internals@lists.php.net'; - $failto = 'group@php.net'; - break; - -case "pear": - $mailto = 'pear-dev@lists.php.net'; - $failto = 'pear-group@php.net'; - break; - -case "pecl": - $mailto = 'pecl-dev@lists.php.net'; - $failto = 'group@php.net'; - break; - -case "doc": - $mailto = 'phpdoc@lists.php.net'; - $failto = 'group@php.net'; - break; - -default: - die ("Unknown group"); -} - -$username = strtolower($username); - -# these are reserved account names. some of them (like webmaster and group) -# are pre-existing mail aliases. others are addresses that get a ton of spam -# that are used as honeypots for blocking spam. (mail to them gets the sender -# placed in qmail-smtpd's badmailfrom to block future emails.) some of these -# latter addresses were used as examples in the documentation at one point, -# which means they appear on all sorts of spam lists. -if (in_array($username,array('nse','roys','php','foo','group','core','webmaster','mysql','web','aardvark','zygote','jag','sites','er'))) - die("that username is not available"); - -@mysql_connect("localhost","nobody", "") - or die("failed to connect to database"); -@mysql_select_db("phpmasterdb") - or die("failed to select database"); - -if (!is_emailable_address(stripslashes($email))) - die("that email address does not appear to be valid"); - -$res = @mysql_query("SELECT userid FROM users WHERE username='$username'"); -if ($res && mysql_num_rows($res)) - die("someone is already using that cvs id"); - -# TODO: fail if someone with that email address has an account. right now -# this goes to the failto address since there's no password recovery -# mechanism -$passwd = stripslashes($passwd); -$cvspasswd = crypt($passwd, substr(md5(time()), 0, 2)); -$md5passwd = md5($passwd); -$svnpasswd = gen_svn_pass($username, $passwd); - -$query = "INSERT INTO users (name,email,passwd,svnpasswd,md5passwd,username) VALUES "; -$query .= "('$name','$email','$cvspasswd','$svnpasswd','$md5passwd','$username')"; - -//echo "<!--$query-->\n"; -if (@mysql_query($query)) { - $new_id = mysql_insert_id(); - - mysql_query("INSERT INTO users_note (userid, note, entered)" - ." VALUES ($new_id, '$note', NOW())"); - - $msg = stripslashes($note); - - $from = '"'.stripslashes($name).'" <'.stripslashes($email).">"; - - // The PEAR guys don't want these requests to their -dev@ list, only -group@ - if ($group != "pear") { - mail($mailto,"CVS Account Request: $username",$msg,"From: $from\r\nMessage-ID: <cvs-account-$new_id@php.net>", "-fnoreply@php.net"); - } - - $msg .= "\n-- \n"; - $msg .= "approve: https://master.php.net/manage/users.php?action=approve&id=$new_id\n"; - $msg .= "reject: https://master.php.net/manage/users.php?action=remove&id=$new_id\n"; - $msg .= "view: https://master.php.net/manage/users.php?id=$new_id\n"; - - mail($failto,"CVS Account Request: $username",$msg,"From: $from\r\nMessage-ID: <cvs-account-$new_id-admin@php.net>", "-fnoreply@php.net"); -} else { - mail($failto,"CVS Account Request: $username", - "Failed to insert into database: ".mysql_error()."\n\n". - "Full name: $name\n". - "Email: $email\n". - "ID: $username\n". - "Password: $cvspasswd\n". - "Purpose: $note", - "From: \"CVS Account Request\" <$email>"); -} Copied: web/php-master/trunk/entry/svn-account.php (from rev 286510, web/php-master/trunk/entry/cvs-account.php) =================================================================== --- web/php-master/trunk/entry/svn-account.php (rev 0) +++ web/php-master/trunk/entry/svn-account.php 2009-07-29 14:40:12 UTC (rev 286511) @@ -0,0 +1,104 @@ +<?php + +require 'email-validation.inc'; +require dirname(__FILE__) . '/../include/svn-auth.inc'; + +if (empty($name) || empty($email) || empty($username) || empty($passwd) || empty($note) || empty($group)) + die("missing some parameters"); + +// Sophisticated security/spam protection question +if (empty($yesno) || $yesno != "yes") { + die("You did not fill the form out correctly"); +} + +switch($group) { +case "php": + $mailto = 'internals@lists.php.net'; + $failto = 'group@php.net'; + break; + +case "pear": + $mailto = 'pear-dev@lists.php.net'; + $failto = 'pear-group@php.net'; + break; + +case "pecl": + $mailto = 'pecl-dev@lists.php.net'; + $failto = 'group@php.net'; + break; + +case "doc": + $mailto = 'phpdoc@lists.php.net'; + $failto = 'group@php.net'; + break; + +default: + die ("Unknown group"); +} + +$username = strtolower($username); + +# these are reserved account names. some of them (like webmaster and group) +# are pre-existing mail aliases. others are addresses that get a ton of spam +# that are used as honeypots for blocking spam. (mail to them gets the sender +# placed in qmail-smtpd's badmailfrom to block future emails.) some of these +# latter addresses were used as examples in the documentation at one point, +# which means they appear on all sorts of spam lists. +if (in_array($username,array('nse','roys','php','foo','group','core','webmaster','mysql','web','aardvark','zygote','jag','sites','er'))) + die("that username is not available"); + +@mysql_connect("localhost","nobody", "") + or die("failed to connect to database"); +@mysql_select_db("phpmasterdb") + or die("failed to select database"); + +if (!is_emailable_address(stripslashes($email))) + die("that email address does not appear to be valid"); + +$res = @mysql_query("SELECT userid FROM users WHERE username='$username'"); +if ($res && mysql_num_rows($res)) + die("someone is already using that cvs id"); + +# TODO: fail if someone with that email address has an account. right now +# this goes to the failto address since there's no password recovery +# mechanism +$passwd = stripslashes($passwd); +$cvspasswd = crypt($passwd, substr(md5(time()), 0, 2)); +$md5passwd = md5($passwd); +$svnpasswd = gen_svn_pass($username, $passwd); + +$query = "INSERT INTO users (name,email,passwd,svnpasswd,md5passwd,username) VALUES "; +$query .= "('$name','$email','$cvspasswd','$svnpasswd','$md5passwd','$username')"; + +//echo "<!--$query-->\n"; +if (@mysql_query($query)) { + $new_id = mysql_insert_id(); + + mysql_query("INSERT INTO users_note (userid, note, entered)" + ." VALUES ($new_id, '$note', NOW())"); + + $msg = stripslashes($note); + + $from = '"'.stripslashes($name).'" <'.stripslashes($email).">"; + + // The PEAR guys don't want these requests to their -dev@ list, only -group@ + if ($group != "pear") { + mail($mailto,"CVS Account Request: $username",$msg,"From: $from\r\nMessage-ID: <cvs-account-$new_id@php.net>", "-fnoreply@php.net"); + } + + $msg .= "\n-- \n"; + $msg .= "approve: https://master.php.net/manage/users.php?action=approve&id=$new_id\n"; + $msg .= "reject: https://master.php.net/manage/users.php?action=remove&id=$new_id\n"; + $msg .= "view: https://master.php.net/manage/users.php?id=$new_id\n"; + + mail($failto,"CVS Account Request: $username",$msg,"From: $from\r\nMessage-ID: <cvs-account-$new_id-admin@php.net>", "-fnoreply@php.net"); +} else { + mail($failto,"CVS Account Request: $username", + "Failed to insert into database: ".mysql_error()."\n\n". + "Full name: $name\n". + "Email: $email\n". + "ID: $username\n". + "Password: $cvspasswd\n". + "Purpose: $note", + "From: \"CVS Account Request\" <$email>"); +}

« previous php.webmaster (#5550) next »