| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | |/ /
| | |/| |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
After the introduction of add_form_key() and check_form_key() calls to
login_box() in phpBB 3.2.6 and later, if a banned user attempts to login,
they receive a "The submitted form was invalid. Try submitting again."
Instead of the message indicating that they are banned, and why.
This is happening because check_ban() actually calls into login_box()
recursively, but after the $user->session_id has been switched to a new
session ID for the logging-on user. Therefore, now that check_form_key()
has been introduced to login_box(), it is impossible for check_form_key()
to succeed during this recursive call.
Fix is to make login_box()'s use of check_form_key() conditional on whether
IN_CHECK_BAN is defined, so that the recursive call does not attempt to
re-validate the form_key again. Note the form_key has already been
successfully verified by the original call into login_box(), prior to calling
into check_ban() and attempting to recursively call login_box(). So the
protection of why check_form_key() was added is still intact with this change.
PHPBB3-16066
|
| |\ \ \ \ \
| |/ / / / |
|
| | |\ \ \ \
| | |/ / /
| |/| | |
| | | | | |
[ticket/15886] Group helper functions
|
| | | | | |
| | | | |
| | | | |
| | | | | |
PHPBB3-15886
|
| | | | | |
| | | | |
| | | | |
| | | | | |
PHPBB3-15886
|
| | | | | |
| | | | |
| | | | |
| | | | | |
PHPBB3-15886
|
| |\ \ \ \ \
| |/ / / / |
|
| | |\ \ \ \
| | | | | |
| | | | | |
| | | | | | |
[ticket/14459] Check language input for group and fix template logic
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-14459
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-14459
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-14459
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-14459
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-14459
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-14459
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-14459
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-14459
|
| | | | |/ /
| | |/| |
| | | | |
| | | | | |
PHPBB3-14459
|
| |\ \ \ \ \
| |/ / / / |
|
| | |\ \ \ \
| | | | | |
| | | | | |
| | | | | | |
[ticket/16013] Allow admins to use disallowed username
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-16013
|
| |\ \ \ \ \ \
| |/ / / / / |
|
| | |\ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | | |
[ticket/16106] Add core.mcp_main_before
|
| | | | |/ / /
| | |/| | |
| | | | | |
| | | | | | |
PHPBB3-16106
|
| |\ \ \ \ \ \
| |/ / / / / |
|
| | |\ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | | |
[ticket/16103] Add core.pm_modify_message_subject
|
| | | |/ / / /
| | | | | |
| | | | | |
| | | | | | |
PHPBB3-16103
|
| |\ \ \ \ \ \
| |/ / / / / |
|
| | |\ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | | |
[ticket/16070] Remove support for WebSTAR and Xitami
|
| | | | |/ / /
| | |/| | |
| | | | | |
| | | | | | |
PHPBB3-16070
|
| |\ \ \ \ \ \
| |/ / / / / |
|
| | |\ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | | |
[ticket/16089] Add core.confirm_box_ajax_before
|
| | | | |/ / /
| | |/| | |
| | | | | |
| | | | | | |
PHPBB3-16089
|
| |\ \ \ \ \ \
| |/ / / / / |
|
| | |\ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | | |
[ticket/15976] Reset user_passchg only if user changed password
|
| | | | |/ / /
| | |/| | |
| | | | | |
| | | | | | |
PHPBB3-15976
|
| |\ \ \ \ \ \
| |/ / / / / |
|
| | |\ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | | |
[ticket/16023] Add core.message_history_modify_template_vars
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
PHPBB3-16023
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
PHPBB3-16023
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
PHPBB3-16023
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
PHPBB3-16023
|
| |\ \ \ \ \ \ \
| |/ / / / / / |
|
| | |\ \ \ \ \ \
| | |_|_|/ / /
| |/| | | | |
| | | | | | | |
[ticket/15961] Use newer TLS in SMTP
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
PHPBB3-15961
|
| |\ \ \ \ \ \ \
| |/ / / / / / |
|
| | |\ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | | |
[ticket/16075] Fix warning in PM filter
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
PHPBB3-16075
|
| |\ \ \ \ \ \ \ \
| |/ / / / / / / |
|
| | |\ \ \ \ \ \ \
| | | | | | | | |
| | | | | | | | |
| | | | | | | | | |
[ticket/15211] Fix Emoji characters in forum name
|
| | | |/ / / / / /
| | | | | | | |
| | | | | | | |
| | | | | | | | |
PHPBB3-15211
|