Re: svn: /web/php-bugs/trunk/ include/functions.php include/query.php include/trusted-devs.php sql/bugs.sql www/bug.php www/css/style.css
www/report.php www/search.php

From: Date: Fri, 19 Nov 2010 11:53:46 +0000
Subject: Re: svn: /web/php-bugs/trunk/ include/functions.php include/query.php include/trusted-devs.php sql/bugs.sql www/bug.php www/css/style.css
www/report.php www/search.php
References: 1  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-9490@lists.php.net to get a copy of this message
On Mon, Nov 15, 2010 at 21:22, Felipe Pena <felipe@php.net> wrote: > felipe                                   Mon, 15 Nov 2010 20:22:55 +0000 > > Revision: > http://svn.php.net/viewvc?view=revision&revision=305382 > > Log: > - Added field to CVE-ID > - Added support to private report >  (When setting the package name to 'Security related', it will turns automatically a > private report) > > private report: Only the original reporter and people behind security@php will can > see/edit/comment it. > > When the report is ok to be public, anyone from security@php can turn it public. > > # Initial commit... :P > > Changed paths: >    U   web/php-bugs/trunk/include/functions.php >    U   web/php-bugs/trunk/include/query.php >    U   web/php-bugs/trunk/include/trusted-devs.php >    U   web/php-bugs/trunk/sql/bugs.sql >    U   web/php-bugs/trunk/www/bug.php >    U   web/php-bugs/trunk/www/css/style.css >    U   web/php-bugs/trunk/www/report.php >    U   web/php-bugs/trunk/www/search.php Modified: web/php-bugs/trunk/www/search.php =================================================================== --- web/php-bugs/trunk/www/search.php 2010-11-15 18:48:48 UTC (rev 305381) +++ web/php-bugs/trunk/www/search.php 2010-11-15 20:22:55 UTC (rev 305382) @@ -13,7 +13,7 @@ $count_only = isset($_REQUEST['count_only']) && $_REQUEST['count_only']; // Authenticate (Disabled for now, searching does not require knowledge of user level) -//bugs_authenticate($user, $pw, $logged_in, $is_trusted_developer); +bugs_authenticate($user, $pw, $logged_in, $is_trusted_developer); The comment is atleast incorrect now :) And not that I am complaining, but $is_trusted_developer isn't actually a list of security@ usernames.. If the plan is to only allow security@ to see the reports then there should probably be a new array of usernames, or atleast the current security@ guys added to the current one (if any are missing). -Hannes

« previous php.webmaster (#9490) next »