phpBMS

Show
Ignore:
Timestamp:
01/06/10 23:35:21 (2 years ago)
Author:
brieb
Message:
  • We bother to program security roles, and then forget to set those roles for the most crucial area - users. Ugh!
Files:
1 modified

Legend:

Unmodified
Added
Removed
  • trunk/phpbms/install/updatev0.98.sql

    r715 r726  
    335335UPDATE `tabledefs` SET 
    336336    `uuid` = 'tbld:afe6d297-b484-4f0b-57d4-1c39412e9dfb', 
     337    `searchroleid` = -100, 
     338    `addroleid` = -100, 
     339    `editroleid` = -100, 
    337340    `prefix` = 'usr' 
    338341WHERE 
     
    341344UPDATE `tabledefs` SET 
    342345    `uuid`='tbld:8d19c73c-42fb-d829-3681-d20b4dbe43b9', 
     346    `searchroleid` = -100, 
     347    `addroleid` = -100, 
     348    `editroleid` = -100, 
    343349    `prefix` = 'rln', 
    344350    `querytable` = '(`relationships` INNER JOIN `tabledefs` AS `fromtable` ON `relationships`.`fromtableid`=`fromtable`.`uuid`) INNER JOIN `tabledefs` AS `totable` ON `relationships`.`totableid`=`totable`.`uuid`' 
     
    361367UPDATE `tabledefs` SET 
    362368    `uuid`='tbld:d595ef42-db9d-2233-1b9b-11dfd0db9cbb', 
     369    `searchroleid` = -100, 
     370    `addroleid` = -100, 
     371    `editroleid` = -100, 
    363372    `prefix` = 'rpt', 
    364373    `querytable` = '`reports` LEFT JOIN `tabledefs` ON `reports`.`tabledefid` = `tabledefs`.`uuid`' 
     
    368377UPDATE `tabledefs` SET 
    369378    `uuid`='tbld:e251524a-2da4-a0c9-8725-d3d0412d8f4a', 
     379    `searchroleid` = -100, 
     380    `addroleid` = -100, 
     381    `editroleid` = -100, 
    370382    `prefix` = 'sss', 
    371383    `querytable` = '(`usersearches` LEFT JOIN `users` ON `usersearches`.`userid` = `users`.`uuid`) INNER JOIN `tabledefs` ON `usersearches`.`tabledefid`=`tabledefs`.`uuid`' 
     
    375387UPDATE `tabledefs` SET 
    376388    `uuid`='tbld:ea159d67-5e89-5b7f-f5a0-c740e147cd73', 
     389    `searchroleid` = -100, 
     390    `addroleid` = -100, 
     391    `editroleid` = -100, 
    377392    `prefix` = 'mod' 
    378393WHERE 
phpBMS vulnerability assesment provided by Orvant Inc. Copyright © 2010 Kreotek, LLC. All Rights reserved.