aboutsummaryrefslogtreecommitdiffstats
path: root/phpBB/includes/acp
diff options
context:
space:
mode:
authorJoas Schilling <nickvergessen@gmx.de>2015-06-04 14:09:22 +0200
committerJoas Schilling <nickvergessen@gmx.de>2015-06-04 14:13:07 +0200
commit9c84b3b5fb488aa2a04f521e4fc070531e0fa02b (patch)
treec592ca90bf1b6314e68de02a3d0338aa820480f2 /phpBB/includes/acp
parent6ca3a30576ae1bac68d5f4ef5dec286f000131ee (diff)
downloadforums-9c84b3b5fb488aa2a04f521e4fc070531e0fa02b.tar
forums-9c84b3b5fb488aa2a04f521e4fc070531e0fa02b.tar.gz
forums-9c84b3b5fb488aa2a04f521e4fc070531e0fa02b.tar.bz2
forums-9c84b3b5fb488aa2a04f521e4fc070531e0fa02b.tar.xz
forums-9c84b3b5fb488aa2a04f521e4fc070531e0fa02b.zip
[ticket/sec-184] Do not output Jabber password to HTML
SECURITY-184
Diffstat (limited to 'phpBB/includes/acp')
-rw-r--r--phpBB/includes/acp/acp_jabber.php7
1 files changed, 5 insertions, 2 deletions
diff --git a/phpBB/includes/acp/acp_jabber.php b/phpBB/includes/acp/acp_jabber.php
index 8d2e9d41a3..284543acd3 100644
--- a/phpBB/includes/acp/acp_jabber.php
+++ b/phpBB/includes/acp/acp_jabber.php
@@ -107,7 +107,10 @@ class acp_jabber
set_config('jab_host', $jab_host);
set_config('jab_port', $jab_port);
set_config('jab_username', $jab_username);
- set_config('jab_password', $jab_password);
+ if ($jab_password !== '********')
+ {
+ set_config('jab_password', $jab_password);
+ }
set_config('jab_package_size', $jab_package_size);
set_config('jab_use_ssl', $jab_use_ssl);
@@ -122,7 +125,7 @@ class acp_jabber
'JAB_HOST' => $jab_host,
'JAB_PORT' => ($jab_port) ? $jab_port : '',
'JAB_USERNAME' => $jab_username,
- 'JAB_PASSWORD' => $jab_password,
+ 'JAB_PASSWORD' => $jab_password !== '' ? '********' : '',
'JAB_PACKAGE_SIZE' => $jab_package_size,
'JAB_USE_SSL' => $jab_use_ssl,
'S_CAN_USE_SSL' => jabber::can_use_ssl(),