Re: svn: /web/php-bugs/trunk/ include/functions.php include/query.php include/trusted-devs.php sql/bugs.sql www/bug.php www/css/style.css
www/report.php www/search.php
| From: | Hannes Magnússon | Date: | Fri, 19 Nov 2010 11:53:46 +0000 |
| Subject: | Re: svn: /web/php-bugs/trunk/ include/functions.php include/query.php include/trusted-devs.php sql/bugs.sql www/bug.php www/css/style.css www/report.php www/search.php |
||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-9490@lists.php.net to get a copy of this message | ||
On Mon, Nov 15, 2010 at 21:22, Felipe Pena <felipe@php.net> wrote:
> felipe Mon, 15 Nov 2010 20:22:55 +0000
>
> Revision:
> http://svn.php.net/viewvc?view=revision&revision=305382
>
> Log:
> - Added field to CVE-ID
> - Added support to private report
> (When setting the package name to 'Security related', it will turns automatically a
> private report)
>
> private report: Only the original reporter and people behind security@php will can
> see/edit/comment it.
>
> When the report is ok to be public, anyone from security@php can turn it public.
>
> # Initial commit... :P
>
> Changed paths:
> U web/php-bugs/trunk/include/functions.php
> U web/php-bugs/trunk/include/query.php
> U web/php-bugs/trunk/include/trusted-devs.php
> U web/php-bugs/trunk/sql/bugs.sql
> U web/php-bugs/trunk/www/bug.php
> U web/php-bugs/trunk/www/css/style.css
> U web/php-bugs/trunk/www/report.php
> U web/php-bugs/trunk/www/search.php
Modified: web/php-bugs/trunk/www/search.php
===================================================================
--- web/php-bugs/trunk/www/search.php 2010-11-15 18:48:48 UTC (rev 305381)
+++ web/php-bugs/trunk/www/search.php 2010-11-15 20:22:55 UTC (rev 305382)
@@ -13,7 +13,7 @@
$count_only = isset($_REQUEST['count_only']) &&
$_REQUEST['count_only'];
// Authenticate (Disabled for now, searching does not require
knowledge of user level)
-//bugs_authenticate($user, $pw, $logged_in, $is_trusted_developer);
+bugs_authenticate($user, $pw, $logged_in, $is_trusted_developer);
The comment is atleast incorrect now :)
And not that I am complaining, but $is_trusted_developer isn't
actually a list of security@ usernames..
If the plan is to only allow security@ to see the reports then there
should probably be a new array of usernames, or atleast the current
security@ guys added to the current one (if any are missing).
-Hannes