svn: /web/php-bugs/trunk/include/ auth.inc

From: Date: Fri, 04 Sep 2009 11:08:28 +0000
Subject: svn: /web/php-bugs/trunk/include/ auth.inc
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-5810@lists.php.net to get a copy of this message
bjori Fri, 04 Sep 2009 11:08:28 +0000 Revision: http://svn.php.net/viewvc?view=revision&revision=288039 Log: Fixed bug#49450 (normal users get developers authentication errors) # Re-enable the authentication errors messages for devs (with set username) Bug: http://bugs.php.net/49450 (Open) Segmentation fault with ArrayObject::offsetSet() Changed paths: U web/php-bugs/trunk/include/auth.inc Modified: web/php-bugs/trunk/include/auth.inc =================================================================== --- web/php-bugs/trunk/include/auth.inc 2009-09-04 11:02:40 UTC (rev 288038) +++ web/php-bugs/trunk/include/auth.inc 2009-09-04 11:08:28 UTC (rev 288039) @@ -23,11 +23,11 @@ $a = @unserialize($s); if (!is_array($a)) { - //echo "Unknown authentication error\n"; + echo "Unknown authentication error<br />\nMaybe master is down?"; exit; } if (isset($a["errno"])) { - //echo "Authentication failed: ", $a["errstr"], "\n"; + echo "Authentication failed: ", $a["errstr"], "\n"; return false; } @@ -42,6 +42,11 @@ // 0 = username, 1 = password $c = explode(':', base64_decode($_COOKIE['MAGIC_COOKIE']), 2); + + if (!$c[0]) { + // The "remember me" for bug reports (non-devs) feature uses MAGIC_COOKIE without username + return false; + } if (!verify_password($c[0], $c[1])) { return false;

« previous php.webmaster (#5810) next »