RTC PR-5.3-dev Pending

User tests: Successful: Unsuccessful:

avatar SniperSister
SniperSister
15 May 2025

Summary of Changes

The phppass library shipped in core does not use a time-safe comparsion method for the hashes. It's not used in core and timing attacks in web apps are generally very difficult to perform, nevertheless a fix is straightforward.

Testing Instructions

Core Review

Actual result BEFORE applying this Pull Request

Non-Timesafe-Compare

Expected result AFTER applying this Pull Request

Timesafe-Compare

Link to documentations

Please select:

  • Documentation link for docs.joomla.org:

  • No documentation changes for docs.joomla.org needed

  • Pull Request link for manual.joomla.org:

  • No documentation changes for manual.joomla.org needed

avatar SniperSister SniperSister - open - 15 May 2025
avatar SniperSister SniperSister - change - 15 May 2025
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 15 May 2025
Category External Library Libraries
avatar brianteeman
brianteeman - comment - 15 May 2025

# Please be sure to update the Version line if you edit this file in any way.
# It is suggested that you leave the main version number intact, but indicate
# your project name (after the slash) and add your own revision information.

avatar SniperSister SniperSister - change - 15 May 2025
Labels Added: PR-5.3-dev
avatar brianteeman
brianteeman - comment - 15 May 2025

also I noticed that in the manifest it refers to 0.3 when this is 0.5

avatar joomla-cms-bot joomla-cms-bot - change - 15 May 2025
Category External Library Libraries Administration External Library Libraries
avatar brianteeman brianteeman - test_item - 15 May 2025 - Tested successfully
avatar brianteeman
brianteeman - comment - 15 May 2025

I have tested this item ✅ successfully on 9674bfb


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/45477.

avatar HLeithner HLeithner - test_item - 15 May 2025 - Tested successfully
avatar HLeithner
HLeithner - comment - 15 May 2025

I have tested this item ✅ successfully on 9674bfb

Syntactical/isolated tested against php versions, works with 5.6+.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/45477.

avatar alikon alikon - change - 15 May 2025
Status Pending Ready to Commit
avatar alikon
alikon - comment - 15 May 2025

RTC


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/45477.

avatar bembelimen bembelimen - change - 19 May 2025
Status Ready to Commit Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2025-05-19 05:52:57
Closed_By bembelimen
Labels Added: RTC
avatar bembelimen bembelimen - close - 19 May 2025
avatar bembelimen bembelimen - merge - 19 May 2025
avatar bembelimen
bembelimen - comment - 19 May 2025

Thx

Add a Comment

Login with GitHub to post a comment