svn: /web/php-bugs/trunk/ include/functions.php include/prepend.php www/bug.php www/report.php www/search.php

From: Date: Fri, 19 Nov 2010 14:35:57 +0000
Subject: svn: /web/php-bugs/trunk/ include/functions.php include/prepend.php www/bug.php www/report.php www/search.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-9496@lists.php.net to get a copy of this message
felipe Fri, 19 Nov 2010 14:35:57 +0000 Revision: http://svn.php.net/viewvc?view=revision&revision=305557 Log: - Added "Security" bug type to control Security bug instead of a package name Changed paths: U web/php-bugs/trunk/include/functions.php U web/php-bugs/trunk/include/prepend.php U web/php-bugs/trunk/www/bug.php U web/php-bugs/trunk/www/report.php U web/php-bugs/trunk/www/search.php Modified: web/php-bugs/trunk/include/functions.php =================================================================== --- web/php-bugs/trunk/include/functions.php 2010-11-19 10:00:10 UTC (rev 305556) +++ web/php-bugs/trunk/include/functions.php 2010-11-19 14:35:57 UTC (rev 305557) @@ -25,6 +25,7 @@ 'Bug' => 'Bug', 'Feature/Change Request' => 'Req', 'Documentation Problem' => 'Doc', + 'Security' => 'Sec Bug' ); // Used in show_state_options() @@ -1209,6 +1210,9 @@ if ($bug_type === 'Documentation Problem') { // Documentation problems *always* go to the doc team $to[] = $docBugEmail; + } else if ($bug_type == 'Security') { + // Security problems *always* go to the sec team + $to[] = $secBugEmail; } else { /* Get package mailing list address */ Modified: web/php-bugs/trunk/include/prepend.php =================================================================== --- web/php-bugs/trunk/include/prepend.php 2010-11-19 10:00:10 UTC (rev 305556) +++ web/php-bugs/trunk/include/prepend.php 2010-11-19 14:35:57 UTC (rev 305557) @@ -41,6 +41,7 @@ $site_url = $site_data['url']; $bugEmail = $site_data['email']; $docBugEmail = $site_data['doc_email']; +$secBugEmail = $site_data['security_email']; $basedir = $site_data['basedir']; define('BUG_PATCHTRACKER_TMPDIR', $site_data['patch_tmp']); define('DATABASE_DSN', "{$site_data['db_extension']}://{$site_data['db_user']}:{$site_data['db_pass']}@{$site_data['db_host']}/{$site_data['db']}"); Modified: web/php-bugs/trunk/www/bug.php =================================================================== --- web/php-bugs/trunk/www/bug.php 2010-11-19 10:00:10 UTC (rev 305556) +++ web/php-bugs/trunk/www/bug.php 2010-11-19 14:35:57 UTC (rev 305557) @@ -258,10 +258,10 @@ // Just trusted dev can change the package name of a Security related bug to another package if ($bug['private'] == 'Y' && !$is_trusted_developer - && $bug['package_name'] == 'Security related' - && $_POST['in']['package_name'] != $bug['package_name']) { + && $bug['bug_type'] == 'Security' + && $_POST['in']['bug_type'] != $bug['bug_type']) { - $errors[] = 'You cannot change the package of a Security related bug!'; + $errors[] = 'You cannot change the bug type of a Security bug!'; } $ncomment = trim($_POST['ncomment']); @@ -296,10 +296,10 @@ } if (!$errors && !($errors = incoming_details_are_valid($_POST['in'], false))) { - // Allow the reporter to change the package to 'Security related', hence mark + // Allow the reporter to change the bug type to 'Security', hence mark // the report as private - if ($bug['private'] == 'N' && $_POST['in']['package_name'] == 'Security related' - && $_POST['in']['package_name'] != $bug['package_name']) { + if ($bug['private'] == 'N' && $_POST['in']['bug_type'] == 'Security' + && $_POST['in']['bug_type'] != $bug['bug_type']) { $is_private = $_POST['in']['private'] = 'Y'; } @@ -384,8 +384,8 @@ } if ($bug['private'] == 'N' && $bug['private'] != $is_private) { - if ($_POST['in']['package_name'] != 'Security related') { - $errors[] = 'Only Security related bugs can be marked as private.'; + if ($_POST['in']['bug_type'] != 'Security') { + $errors[] = 'Only Security bugs can be marked as private.'; } } @@ -461,8 +461,8 @@ } // Changing the package to 'Security related' should mark the bug as private automatically - if ($bug['package_name'] != $_POST['in']['package_name']) { - if ($_POST['in']['package_name'] == 'Security related') { + if ($bug['bug_type'] != $_POST['in']['bug_type']) { + if ($_POST['in']['bug_type'] == 'Security') { if ($_POST['in']['status'] != 'Closed') { $is_private = $_POST['in']['private'] = 'Y'; } @@ -551,6 +551,8 @@ case 'Documentation Problem': $bug_type = 'Doc Bug'; break; + case 'Security': + $bug_type = 'Sec Bug'; default: case 'Bug': $bug_type = 'Bug'; Modified: web/php-bugs/trunk/www/report.php =================================================================== --- web/php-bugs/trunk/www/report.php 2010-11-19 10:00:10 UTC (rev 305556) +++ web/php-bugs/trunk/www/report.php 2010-11-19 14:35:57 UTC (rev 305557) @@ -162,7 +162,8 @@ exit; } - $is_private = ($package_name == 'Security related' ? 'Y' : 'N'); + // Bug type 'Security' marks automatically the report as private + $is_private = ($_POST['in']['bug_type'] == 'Security') ? 'Y' : 'N'; $res = $dbh->prepare(' INSERT INTO bugdb ( Modified: web/php-bugs/trunk/www/search.php =================================================================== --- web/php-bugs/trunk/www/search.php 2010-11-19 10:00:10 UTC (rev 305556) +++ web/php-bugs/trunk/www/search.php 2010-11-19 14:35:57 UTC (rev 305557) @@ -12,7 +12,6 @@ // For bug count only, used in places like doc.php.net $count_only = isset($_REQUEST['count_only']) && $_REQUEST['count_only']; -// Authenticate (Disabled for now, searching does not require knowledge of user level) bugs_authenticate($user, $pw, $logged_in, $is_trusted_developer); $newrequest = http_build_query(array_merge($_GET, $_POST));

« previous php.webmaster (#9496) next »