bug #1501027, possible user/password disclosure
This commit is contained in:
@@ -5,6 +5,10 @@ phpMyAdmin - ChangeLog
|
|||||||
$Id$
|
$Id$
|
||||||
$Source$
|
$Source$
|
||||||
|
|
||||||
|
2006-06-23 Marc Delisle <lem9@users.sourceforge.net>
|
||||||
|
* libraries/Config.class.php: bug #1501027, possible user/password
|
||||||
|
disclosure when switching from http to https
|
||||||
|
|
||||||
2006-06-22 Marc Delisle <lem9@users.sourceforge.net>
|
2006-06-22 Marc Delisle <lem9@users.sourceforge.net>
|
||||||
* libraries/database_interface.lib.php, /export/sql.php, lang/*:
|
* libraries/database_interface.lib.php, /export/sql.php, lang/*:
|
||||||
export of procedures and functions. Note: this needs improvement
|
export of procedures and functions. Note: this needs improvement
|
||||||
|
@@ -509,7 +509,9 @@ class PMA_Config
|
|||||||
// Setup a default value to let the people and lazy syadmins work anyway,
|
// Setup a default value to let the people and lazy syadmins work anyway,
|
||||||
// they'll get an error if the autodetect code doesn't work
|
// they'll get an error if the autodetect code doesn't work
|
||||||
$pma_absolute_uri = $this->get('PmaAbsoluteUri');
|
$pma_absolute_uri = $this->get('PmaAbsoluteUri');
|
||||||
if (strlen($pma_absolute_uri) < 1) {
|
// by recomputing $pma_absolute_uri when is_https, we ensure
|
||||||
|
// that a user switching from http to https stays in https
|
||||||
|
if (strlen($pma_absolute_uri) < 1 || $this->get('is_https')) {
|
||||||
$url = array();
|
$url = array();
|
||||||
|
|
||||||
// At first we try to parse REQUEST_URI, it might contain full URL
|
// At first we try to parse REQUEST_URI, it might contain full URL
|
||||||
|
Reference in New Issue
Block a user