18 Commits

Author SHA1 Message Date
bbaetz%acm.org
2b0b42744f Bug 180642 - Move authentication code into a module
r=gerv, justdave
a=justdave


git-svn-id: svn://10.0.0.236/trunk@140041 18797224-902f-48f8-a5cc-f745e15eee43
2003-03-22 04:47:35 +00:00
justdave%syndicomm.com
6485d4afc4 Bug 193989: EmailSuffix wasn't getting used for password change tokens. Also removes real name from To: header which wasn't being escaped properly for RFC2822 specs.
Patch by Jeff Lawson <jlawson-mozilla@bovine.net>
r=justdave, a=justdave


git-svn-id: svn://10.0.0.236/trunk@139436 18797224-902f-48f8-a5cc-f745e15eee43
2003-03-14 05:43:38 +00:00
gerv%gerv.net
1ecd0b7779 Bug 164038 - token.cgi: Cancel token messages should be moved into the templates. Patch by burnus; r=gerv.
git-svn-id: svn://10.0.0.236/trunk@130789 18797224-902f-48f8-a5cc-f745e15eee43
2002-09-30 07:22:44 +00:00
bbaetz%student.usyd.edu.au
46d483962b Bug 163829 - move pref code into a separate package
r=joel, preed


git-svn-id: svn://10.0.0.236/trunk@128451 18797224-902f-48f8-a5cc-f745e15eee43
2002-08-29 09:25:54 +00:00
bbaetz%student.usyd.edu.au
71381b40ed Bug 76923 - Don't |use diagnostics| (its really expensive at startup time)
r=joel x2


git-svn-id: svn://10.0.0.236/trunk@128080 18797224-902f-48f8-a5cc-f745e15eee43
2002-08-26 06:17:26 +00:00
myk%mozilla.org
537f75ea7e Fix for bug 150925: make email address changes work.
2xr=bbaetz


git-svn-id: svn://10.0.0.236/trunk@124804 18797224-902f-48f8-a5cc-f745e15eee43
2002-07-09 02:16:56 +00:00
gerv%gerv.net
c66a8b94a7 Bug 135836 - change requests should include expiration details. Patch by zeroJ@null.net; r=gerv, justdave.
git-svn-id: svn://10.0.0.236/trunk@120675 18797224-902f-48f8-a5cc-f745e15eee43
2002-05-03 06:37:47 +00:00
gerv%gerv.net
73101104b9 Bug 135817 - update template filename. Oops.
git-svn-id: svn://10.0.0.236/trunk@119949 18797224-902f-48f8-a5cc-f745e15eee43
2002-04-26 06:46:16 +00:00
gerv%gerv.net
7e5eb805ff Bug 135814 - templatise Token.pm. Patch by zeroj; 2xr=bbaetz.
git-svn-id: svn://10.0.0.236/trunk@119943 18797224-902f-48f8-a5cc-f745e15eee43
2002-04-26 06:01:30 +00:00
gerv%gerv.net
f57c616c0a Bug 136180 - use uri/url_quote filters correctly. Patch by ddk; 2xr=gerv.
git-svn-id: svn://10.0.0.236/trunk@119723 18797224-902f-48f8-a5cc-f745e15eee43
2002-04-24 18:27:43 +00:00
gerv%gerv.net
c8a771fb68 Bug 138588 - change to use new template structure. Patch by gerv, r=myk, afranke.
git-svn-id: svn://10.0.0.236/trunk@119695 18797224-902f-48f8-a5cc-f745e15eee43
2002-04-24 07:24:50 +00:00
justdave%syndicomm.com
45f5cf551d Remaining pieces of Bug 23067 from yesterday... no idea why the first commit didn't pick these up.
git-svn-id: svn://10.0.0.236/trunk@117881 18797224-902f-48f8-a5cc-f745e15eee43
2002-04-01 22:52:40 +00:00
justdave%syndicomm.com
b74c77bfa4 Fix for bug 125516: the recent fix for emails truncating when a period occurred on a line by itself broke Exim because it
needs the -t and -i as separate parameters instead of stacked (the original patch had -ti)
Patch by Tobias Burnus <burnus@gmx.de>
r= justdave, gerv


git-svn-id: svn://10.0.0.236/trunk@114723 18797224-902f-48f8-a5cc-f745e15eee43
2002-02-17 08:22:31 +00:00
justdave%syndicomm.com
686d81fb26 Fix for bug 117055: Emails were being truncated if they contained a line with nothing but a period on them. We now pass -i to
sendmail and its clones to tell it to ignore periods (since we close the pipe when we're done, rather than signalling it with
a period).  Has been tested with sendmail and postfix.
Patch by Dave Miller <justdave@syndicomm.com>
r= afranke, bugzilla@bkor.dhs.org, jake


git-svn-id: svn://10.0.0.236/trunk@113739 18797224-902f-48f8-a5cc-f745e15eee43
2002-02-06 02:47:00 +00:00
justdave%syndicomm.com
c148fadef8 Fix for bug 108982: enable taint mode for all user-facing CGI files.
Patch by Brad Baetz <bbaetz@student.usyd.edu.au>
r= jake, justdave


git-svn-id: svn://10.0.0.236/trunk@112490 18797224-902f-48f8-a5cc-f745e15eee43
2002-01-20 01:44:52 +00:00
justdave%syndicomm.com
715a4d1008 Fix for bug 95731: "INSERT INTO shadowlog" failed because "Table 'shadowlog' not locked", fixed typo in lock tables command.
Patch by Myk Melez <myk@mozilla.org>
r= justdave@syndicomm.com


git-svn-id: svn://10.0.0.236/trunk@101285 18797224-902f-48f8-a5cc-f745e15eee43
2001-08-17 08:38:54 +00:00
justdave%syndicomm.com
427dc35f2e Fix for bug 95535: the token generator for password resets is allowing the & character to be used for tokens, but wasn't escaping them for the URL it emailed to users to use to get in to reset their password.
Patch by Dave Miller <justdave@syndicomm.com>
r= myk@mozilla.org


git-svn-id: svn://10.0.0.236/trunk@101195 18797224-902f-48f8-a5cc-f745e15eee43
2001-08-16 06:52:55 +00:00
justdave%syndicomm.com
a32206490b Fix for bug 77473, bug 74032, and bug 85472: Passwords are no longer stored in plaintext in the database. Passwords are no longer encrypted with MySQL's ENCRYPT() function (because it doesn't work on some installs), but with Perl's crypt() function. The crypt-related routines now properly deal with salts so that they work on systems that use methods other than UNIX crypt to crypt the passwords (such as MD5). Checksetup.pl will walk through your database and re-crypt everyone's passwords based on the plaintext password entry, then drop the plaintext password column. As a consequence of no longer having a plaintext password, it is no longer possible to email someone their password, so the login screen has been changed to request a password reset instead. The user is emailed a temporary identifying token, with a link back to Bugzilla. They click on the link or paste it into their browser and Bugzilla allows them to change their password.
Patch by Myk Melez <myk@mozilla.org>
r= justdave@syndicomm.com, jake@acutex.net


git-svn-id: svn://10.0.0.236/trunk@99057 18797224-902f-48f8-a5cc-f745e15eee43
2001-07-11 05:29:21 +00:00