PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
[ start all new proposals below, under PATCHES PROPOSED. ]
- * sync htdigest with trunk to fix overflows and pick up other minor tweaks
- Trunk patches: http://svn.apache.org/viewvc?view=revision&revision=826506
- http://svn.apache.org/viewvc?view=revision&revision=826520
- http://svn.apache.org/viewvc?view=revision&revision=826528
- http://svn.apache.org/viewvc?view=revision&revision=987498
- 2.2.x patch: http://people.apache.org/~trawick/htdigest-sync.txt
- +1: trawick, poirier, rpluem
PATCHES PROPOSED TO BACKPORT FROM TRUNK:
[ New proposals should be added at the end of the list ]
char *pw;
apr_md5_ctx_t context;
unsigned char digest[16];
- char string[MAX_STRING_LEN];
+ char string[3 * MAX_STRING_LEN]; /* this includes room for 2 * ':' + '\0' */
char pwin[MAX_STRING_LEN];
char pwv[MAX_STRING_LEN];
unsigned int i;
apr_file_printf(f, "%s:%s:", user, realm);
/* Do MD5 stuff */
- sprintf(string, "%s:%s:%s", user, realm, pw);
+ apr_snprintf(string, sizeof(string), "%s:%s:%s", user, realm, pw);
apr_md5_init(&context);
#if APR_CHARSET_EBCDIC
char *dirname;
char user[MAX_STRING_LEN];
char realm[MAX_STRING_LEN];
- char line[MAX_STRING_LEN];
- char l[MAX_STRING_LEN];
+ char line[3 * MAX_STRING_LEN];
+ char l[3 * MAX_STRING_LEN];
char w[MAX_STRING_LEN];
char x[MAX_STRING_LEN];
int found;
apr_strerror(rv, errmsg, sizeof errmsg));
exit(1);
}
+ apr_cpystrn(user, argv[4], sizeof(user));
+ apr_cpystrn(realm, argv[3], sizeof(realm));
apr_file_printf(errfile, "Adding password for %s in realm %s.\n",
- argv[4], argv[3]);
- add_password(argv[4], argv[3], f);
+ user, realm);
+ add_password(user, realm, f);
apr_file_close(f);
exit(0);
}
apr_cpystrn(realm, argv[2], sizeof(realm));
found = 0;
- while (!(get_line(line, MAX_STRING_LEN, f))) {
+ while (!(get_line(line, sizeof(line), f))) {
if (found || (line[0] == '#') || (!line[0])) {
putline(tfp, line);
continue;