From: Jo R. <jr...@sv...> - 2006-09-16 22:25:49
|
> >On Thu, Mar 23, 2006 at 10:28:09AM -0600, Jim Hu wrote: > >>Vuln #2 is related to the publish scripts, which we technically say > >>we don't support. We may need someone to take this on. Anybody? > On Apr 27, 2006, at 9:42 PM, Jo Rhett wrote: > >I'll own it. My apologies for the extreme late delay getting to this. Attached is an updated publish.php. It has the following changes: 1. It fixes the security problem mentioned above. 2. It integrates publish.ical.php and publish.mozilla.php into a single file again. No need to have two files. 3. It supports external authentication (ie .htaccess) for CGI users 4. It supports php authentication with mod_rewrite but without mod_php 5. Logging is improved 6. Internal Documentation is updated and clarified for Sunbird/Lightning users. (the docs may not work for old Mozilla cal users, but I don't know anyone who still has this -- testers?) 7. Minor code cleanup to be consistent with the rest of the code base. And from this point forward I'll start looking at bugs in the sourceforge system and taking on those related to publish. Sorry for the delay. -- Jo Rhett senior geek SVcolo : Silicon Valley Colocation |