Changed the way password validation works. We now keep a
crypt'd version of the password in the database, and check against that. (This is silly, because we're also keeping the plaintext version there, but I have plans...) Stop passing the plaintext password around as a cookie; instead, we have a cookie that references a record in a new database table, logincookies. IMPORTANT: if updating from an older version of Bugzilla, you must run the following commands to keep things working: ./makelogincookiestable.sh echo "alter table profiles add column cryptpassword varchar(64);" | mysql bugs echo "update profiles set cryptpassword = encrypt(password,substring(rand(),3, 4));" | mysql bugs git-svn-id: svn://10.0.0.236/trunk@9121 18797224-902f-48f8-a5cc-f745e15eee43
This commit is contained in:
@@ -66,7 +66,11 @@ Please click <b>Back</b> and try again."
|
||||
|
||||
puts "Content-type: text/html\n"
|
||||
|
||||
SendSQL "update profiles set password='$pwd' where login_name='[SqlQuote $COOKIE(Bugzilla_login)]'"
|
||||
SendSQL "select encrypt('$pwd')"
|
||||
set encrypted [lindex [FetchSQLData] 0]
|
||||
|
||||
SendSQL "update profiles set password='$pwd',cryptpassword='$encrypted' where login_name='[SqlQuote $COOKIE(Bugzilla_login)]'"
|
||||
SendSQL "update logincookies set cryptpassword = '$encrypted' where cookie = $COOKIE(Bugzilla_logincookie)"
|
||||
|
||||
puts "<H1>OK, done.</H1>
|
||||
Your new password has been set.
|
||||
|
||||
Reference in New Issue
Block a user