Re: svn: /web/php-bugs/trunk/ include/functions.php include/query.php include/trusted-devs.php sql/bugs.sql www/bug.php www/css/style.css
www/report.php www/search.php
| From: | Felipe Pena | Date: | Fri, 19 Nov 2010 13:31:33 +0000 |
| Subject: | Re: svn: /web/php-bugs/trunk/ include/functions.php include/query.php include/trusted-devs.php sql/bugs.sql www/bug.php www/css/style.css www/report.php www/search.php |
||
| References: | 1 2 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-9495@lists.php.net to get a copy of this message | ||
2010/11/19 Hannes Magnússon <hannes.magnusson@gmail.com>
> On Mon, Nov 15, 2010 at 21:22, Felipe Pena <felipe@php.net> wrote:
> > felipe Mon, 15 Nov 2010 20:22:55 +0000
> >
> > Revision:
> > http://svn.php.net/viewvc?view=revision&revision=305382
> >
> > Log:
> > - Added field to CVE-ID
> > - Added support to private report
> > (When setting the package name to 'Security related', it will turns
> automatically a private report)
> >
> > private report: Only the original reporter and people behind security@phpwill can
> > see/edit/comment it.
> >
> > When the report is ok to be public, anyone from security@php can turn it
> public.
> >
> > # Initial commit... :P
> >
> > Changed paths:
> > U web/php-bugs/trunk/include/functions.php
> > U web/php-bugs/trunk/include/query.php
> > U web/php-bugs/trunk/include/trusted-devs.php
> > U web/php-bugs/trunk/sql/bugs.sql
> > U web/php-bugs/trunk/www/bug.php
> > U web/php-bugs/trunk/www/css/style.css
> > U web/php-bugs/trunk/www/report.php
> > U web/php-bugs/trunk/www/search.php
>
>
> Modified: web/php-bugs/trunk/www/search.php
> ===================================================================
> --- web/php-bugs/trunk/www/search.php 2010-11-15 18:48:48 UTC (rev
> 305381)
> +++ web/php-bugs/trunk/www/search.php 2010-11-15 20:22:55 UTC (rev
> 305382)
> @@ -13,7 +13,7 @@
> $count_only = isset($_REQUEST['count_only']) &&
> $_REQUEST['count_only'];
>
> // Authenticate (Disabled for now, searching does not require
> knowledge of user level)
> -//bugs_authenticate($user, $pw, $logged_in, $is_trusted_developer);
> +bugs_authenticate($user, $pw, $logged_in, $is_trusted_developer);
>
> The comment is atleast incorrect now :)
>
>
Yes, I'll remove it... :P
> And not that I am complaining, but $is_trusted_developer isn't
> actually a list of security@ usernames..
> If the plan is to only allow security@ to see the reports then there
> should probably be a new array of usernames, or atleast the current
> security@ guys added to the current one (if any are missing).
>
>
Yes, this is the plan... But I didn't got the such list yet... ;)
So I am testing with the actual trusted devs one...
--
Regards,
Felipe Pena