Skip to content

Fix validation findings - #39

Merged
bonelifer merged 1 commit into
masterfrom
validation-fixes
Oct 7, 2026
Merged

bonelifer merged 1 commit into
masterfrom
validation-fixes

Conversation

@bonelifer

Copy link
Copy Markdown
Contributor

Fixes everything a phpBB.com-style validation pass found on 1.5.0, before it is uploaded to the Extensions Database. The version stays at 1.5.0, since that version has not been released yet.

Security

  • ACP bot lookup route: /contact_bot_info/{user_id} had no permission check. Anyone, including guests on boards that hide profiles, could step through user ids and read usernames and account types. It now requires a_board and always returns JSON. Without AJAX it previously failed with a server error.

Bugs

  • Event data: when the contact bot posts for the sender, modify_data_and_error listeners such as Stop Forum Spam saw the bot's name instead of the sender's. The bot name is now only used for the post itself.
  • ACP preview: the preview overwrote the BBCode uid and bitfield, so BBCode didn't render.
  • Guest email check: a misspelled setting name meant guests could get the same email error twice.
  • No-contact error page: the "return to index" link was dropped.
  • Error emails: a host name was set as the From address. The board email address is now used.
  • PMs to admins: one PM goes to all admins as blind copies, instead of one PM per admin.

Validation and cleanup

  • JavaScript and CSS moved out of the templates into files included with INCLUDEJS / INCLUDECSS.
  • The reason and forum drop downs are built in templates.
  • Choices that must be one of a fixed set are validated when saved.
  • Removed unused code, config reads (contactadmin_founder_only, the always-true phpBB version check) and three unused language keys. Keys that overrode phpBB core keys are prefixed.
  • ADMINS_NOT_EXIST_FOR_METHOD is split into two keys instead of misusing plural forms.
  • Declared properties and docblocks.
  • composer.json: tab indentation and a bounded phpBB requirement.
  • license.txt now uses the extension skeleton's text.

Testing

Claude ran these on a local phpBB 3.3.19 test board (PHP 8.4):

  • Smoke test: clean.
  • 18 targeted runtime checks, including:
    • the bot lookup refused for guests and returning JSON for admins, with and without AJAX;
    • the ACP JS/CSS files served, with no inline script left;
    • the BBCode preview;
    • invalid ACP choices falling back to allowed values;
    • the reasons drop down and the stylesheet on the contact form;
    • a single email error for guests;
    • a real guest submission delivering one PM to the admins as a blind copy;
    • an empty PHP error log.
  • The ACP JavaScript passes node --check. It was not exercised in a browser.
  • Codex reviewed the diff and found no regressions.

Investigated and written by Claude on behalf of William Jacoby (bonelifer).

🤖 Generated with Claude Code

Fixes everything a phpBB.com-style validation pass found:

- The ACP bot lookup route (/contact_bot_info/{user_id}) had no permission check, so anyone could read usernames and account types; it now requires a_board and always returns JSON.
- When the contact bot posts for the sender, modify_data_and_error listeners such as Stop Forum Spam saw the bot's name instead of the sender's; the bot name is now only used for the post.
- The ACP preview overwrote the BBCode uid and bitfield, so BBCode didn't render.
- The email check read a misspelled setting, so guests could get the same email error twice.
- The "return to index" link on the no-contact error page was dropped, and error emails set a host name as the From address.
- One PM to all admins as blind copies instead of one PM per admin.
- JavaScript and CSS moved out of the templates into files included with INCLUDEJS / INCLUDECSS; drop downs built in templates; settings that must be one of a fixed set are validated.
- Unused code, config reads and language keys removed; keys that overrode phpBB core keys prefixed; ADMINS_NOT_EXIST_FOR_METHOD split into two keys instead of using plural forms.
- Declared properties, docblocks, composer.json tab indentation and a bounded phpBB requirement, license.txt from the extension skeleton.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@bonelifer
bonelifer merged commit 2292492 into master Oct 7, 2026
3 checks passed
@bonelifer
bonelifer deleted the validation-fixes branch October 7, 2026 01:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant