Repository navigation
Fix validation findings - #39
Merged
Merged
Conversation
Fixes everything a phpBB.com-style validation pass found:
- The ACP bot lookup route (/contact_bot_info/{user_id}) had no permission check, so anyone could read usernames and account types; it now requires a_board and always returns JSON.
- When the contact bot posts for the sender, modify_data_and_error listeners such as Stop Forum Spam saw the bot's name instead of the sender's; the bot name is now only used for the post.
- The ACP preview overwrote the BBCode uid and bitfield, so BBCode didn't render.
- The email check read a misspelled setting, so guests could get the same email error twice.
- The "return to index" link on the no-contact error page was dropped, and error emails set a host name as the From address.
- One PM to all admins as blind copies instead of one PM per admin.
- JavaScript and CSS moved out of the templates into files included with INCLUDEJS / INCLUDECSS; drop downs built in templates; settings that must be one of a fixed set are validated.
- Unused code, config reads and language keys removed; keys that overrode phpBB core keys prefixed; ADMINS_NOT_EXIST_FOR_METHOD split into two keys instead of using plural forms.
- Declared properties, docblocks, composer.json tab indentation and a bounded phpBB requirement, license.txt from the extension skeleton.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes everything a phpBB.com-style validation pass found on 1.5.0, before it is uploaded to the Extensions Database. The version stays at 1.5.0, since that version has not been released yet.
Security
/contact_bot_info/{user_id}had no permission check. Anyone, including guests on boards that hide profiles, could step through user ids and read usernames and account types. It now requiresa_boardand always returns JSON. Without AJAX it previously failed with a server error.Bugs
modify_data_and_errorlisteners such as Stop Forum Spam saw the bot's name instead of the sender's. The bot name is now only used for the post itself.Validation and cleanup
INCLUDEJS/INCLUDECSS.contactadmin_founder_only, the always-true phpBB version check) and three unused language keys. Keys that overrode phpBB core keys are prefixed.ADMINS_NOT_EXIST_FOR_METHODis split into two keys instead of misusing plural forms.composer.json: tab indentation and a bounded phpBB requirement.license.txtnow uses the extension skeleton's text.Testing
Claude ran these on a local phpBB 3.3.19 test board (PHP 8.4):
node --check. It was not exercised in a browser.Investigated and written by Claude on behalf of William Jacoby (bonelifer).
🤖 Generated with Claude Code