View Single Post
  #3  
Old 05-17-2009, 04:06 AM
smokey's Avatar
smokey smokey is offline
 
Join Date: Nov 2001
Location: North Carolina
Posts: 32
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Nothing wrong with the plugin. The variable simply is not set or empty, all that is set is the newpassword_md5. I'm just trying to figure out why and a work around. The code is fine.

Anyone?

The default code in profile.php

PHP Code:
// ############################### start update password ###############################
if ($_POST['do'] == 'updatepassword')
{
    
$vbulletin->input->clean_array_gpc('p', array(
        
'currentpassword'        => TYPE_STR,
        
'currentpassword_md5'    => TYPE_STR,
        
'newpassword'            => TYPE_STR,
        
'newpasswordconfirm'     => TYPE_STR,
        
'newpassword_md5'        => TYPE_STR,
        
'newpasswordconfirm_md5' => TYPE_STR,
        
'email'                  => TYPE_STR,
        
'emailconfirm'           => TYPE_STR
    
));

    
// instanciate the data manager class
    
$userdata =& datamanager_init('user'$vbulletinERRTYPE_STANDARD);
    
$userdata->set_existing($vbulletin->userinfo);

    (
$hook vBulletinHook::fetch_hook('profile_updatepassword_start')) ? eval($hook) : false;

    
// validate old password
    
if ($userdata->hash_password($userdata->verify_md5($vbulletin->GPC['currentpassword_md5']) ? $vbulletin->GPC['currentpassword_md5'] : $vbulletin->GPC['currentpassword'], $vbulletin->userinfo['salt']) != $vbulletin->userinfo['password'])
    {
        eval(
standard_error(fetch_error('badpassword'$vbulletin->options['bburl'], $vbulletin->session->vars['sessionurl'])));
    }

    
// update password
    
if (!empty($vbulletin->GPC['newpassword']) OR !empty($vbulletin->GPC['newpassword_md5']))
    {
        
// are we using javascript-hashed password strings?
        
if ($userdata->verify_md5($vbulletin->GPC['newpassword_md5']))
        {
            
$vbulletin->GPC['newpassword'] =& $vbulletin->GPC['newpassword_md5'];
            
$vbulletin->GPC['newpasswordconfirm'] =& $vbulletin->GPC['newpasswordconfirm_md5'];
        }
        else
        {
            
$vbulletin->GPC['newpassword'] =& md5($vbulletin->GPC['newpassword']);
            
$vbulletin->GPC['newpasswordconfirm'] =& md5($vbulletin->GPC['newpasswordconfirm']);
        }

        
// check that new passwords match
        
if ($vbulletin->GPC['newpassword'] != $vbulletin->GPC['newpasswordconfirm'])
        {
            eval(
standard_error(fetch_error('passwordmismatch')));
        } 
My code is parsed at that hook location.

This is empty:
PHP Code:
$vbulletin->GPC['newpassword'
and...
PHP Code:
$vbulletin->GPC['newpasswordconfirm'
But this is not:

PHP Code:
$vbulletin->GPC['newpassword_md5'
The hook executes before:

PHP Code:
    if (!empty($vbulletin->GPC['newpassword']) OR !empty($vbulletin->GPC['newpassword_md5']))
    {
        
// are we using javascript-hashed password strings?
        
if ($userdata->verify_md5($vbulletin->GPC['newpassword_md5']))
        {
            
$vbulletin->GPC['newpassword'] =& $vbulletin->GPC['newpassword_md5']; 
So how is that string empty? It doesn't make any since to me

--------------- Added [DATE]1242606969[/DATE] at [TIME]1242606969[/TIME] ---------------

I figured it out after heavy investigating. Javascript in the modifypassword template was actually doing the conversion to submit to the forum as a hashed password thus not sending the clear text password.

Hope this helps anyone else who may need to accomplish the same thing in the future.
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01103 seconds
  • Memory Usage 1,821KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (5)bbcode_php
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete