<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://pkp.sfu.ca/bugzilla/bugzilla.dtd">

<bugzilla version="4.2.5+"
          urlbase="http://pkp.sfu.ca/bugzilla/"
          
          maintainer="pkp-hosted@sfu.ca"
>

    <bug>
          <bug_id>6458</bug_id>
          
          <creation_ts>2011-03-01 22:15:00 -0800</creation_ts>
          <short_desc>Subscription verification bypassed with custom galley identifiers</short_desc>
          <delta_ts>2011-03-08 15:34:57 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>OJS</product>
          <component>Subscriptions</component>
          <version>2.3.5</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Michael Felczak">michael.pkp</reporter>
          <assigned_to name="Michael Felczak">michael.pkp</assigned_to>
          <cc>alec</cc>
    
    <cc>bozana.bokan</cc>
    
    <cc>pkp-support</cc>
          <cf_reportedversion>2.3.4</cf_reportedversion>
          

      

      

      

          <long_desc isprivate="0">
            <commentid>23012</commentid>
            <who name="Michael Felczak">michael.pkp</who>
            <bug_when>2011-03-01 22:15:20 -0800</bug_when>
            <thetext></thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>23013</commentid>
              <attachid>3442</attachid>
            <who name="Michael Felczak">michael.pkp</who>
            <bug_when>2011-03-01 22:50:12 -0800</bug_when>
            <thetext>Created attachment 3442
Patch against OJS 2.3.3 to OJS 2.3.3-3</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>23014</commentid>
              <attachid>3443</attachid>
            <who name="Michael Felczak">michael.pkp</who>
            <bug_when>2011-03-01 22:50:36 -0800</bug_when>
            <thetext>Created attachment 3443
Patch against OJS 2.3.4</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>23057</commentid>
            <who name="Michael Felczak">michael.pkp</who>
            <bug_when>2011-03-04 09:01:34 -0800</bug_when>
            <thetext>*** Bug 6470 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>23094</commentid>
            <who name="Michael Felczak">michael.pkp</who>
            <bug_when>2011-03-08 11:38:02 -0800</bug_when>
            <thetext>Fixed:

https://github.com/pkp/ojs/commit/21e1e5e386d5a12daba8aade7da5781c95fb8583</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>23106</commentid>
            <who name="Alec Smecher">alec</who>
            <bug_when>2011-03-08 15:34:57 -0800</bug_when>
            <thetext>(Committed to ojs-stable-2_3)</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3442</attachid>
            <date>2011-03-01 22:50:00 -0800</date>
            <delta_ts>2011-03-01 22:50:12 -0800</delta_ts>
            <desc>Patch against OJS 2.3.3 to OJS 2.3.3-3</desc>
            <filename>6458_ojs_2_3_3.diff</filename>
            <type>text/plain</type>
            <size>1908</size>
            <attacher>michael.pkp</attacher>
            
              <data encoding="base64">LS0tIGEvcGFnZXMvYXJ0aWNsZS9BcnRpY2xlSGFuZGxlci5pbmMucGhwCTIwMTEtMDMtMDEgMjI6
MzY6NTMuMDAwMDAwMDAwIC0wODAwCisrKyBiL3BhZ2VzL2FydGljbGUvQXJ0aWNsZUhhbmRsZXIu
aW5jLnBocAkyMDExLTAzLTAxIDIyOjM3OjU5LjAwMDAwMDAwMCAtMDgwMApAQCAtNDEzLDcgKzQx
Myw3IEBACiAJICogQHNlZSBsaWIvcGtwL2NsYXNzZXMvaGFuZGxlci9QS1BIYW5kbGVyI3ZhbGlk
YXRlKCkKIAkgKiBAcGFyYW0gJHJlcXVlc3QgUmVxdWVzdAogCSAqIEBwYXJhbSAkYXJ0aWNsZUlk
IGludGVnZXIKLQkgKiBAcGFyYW0gJGdhbGxleUlkIGludGVnZXIKKwkgKiBAcGFyYW0gJGdhbGxl
eUlkIGludCBvciBzdHJpbmcKIAkgKi8KIAlmdW5jdGlvbiB2YWxpZGF0ZSgmJHJlcXVlc3QsICRh
cnRpY2xlSWQsICRnYWxsZXlJZCA9IG51bGwpIHsKIAkJJHJvdXRlciA9JiAkcmVxdWVzdC0+Z2V0
Um91dGVyKCk7CkBAIC00NjAsMTQgKzQ2MCwxNCBAQAogCQkJJGlzU3Vic2NyaWJlZERvbWFpbiA9
IElzc3VlQWN0aW9uOjpzdWJzY3JpYmVkRG9tYWluKCRqb3VybmFsLCAkaXNzdWUtPmdldElkKCks
ICRhcnRpY2xlSWQpOwogCiAJCQkvLyBDaGVjayBpZiBsb2dpbiBpcyByZXF1aXJlZCBmb3Igdmll
d2luZy4KLQkJCWlmICghJGlzU3Vic2NyaWJlZERvbWFpbiAmJiAhVmFsaWRhdGlvbjo6aXNMb2dn
ZWRJbigpICYmICRqb3VybmFsLT5nZXRTZXR0aW5nKCdyZXN0cmljdEFydGljbGVBY2Nlc3MnKSAm
JiBpc3NldCgkZ2FsbGV5SWQpICYmICRnYWxsZXlJZCAhPSAwKSB7CisJCQlpZiAoISRpc1N1YnNj
cmliZWREb21haW4gJiYgIVZhbGlkYXRpb246OmlzTG9nZ2VkSW4oKSAmJiAkam91cm5hbC0+Z2V0
U2V0dGluZygncmVzdHJpY3RBcnRpY2xlQWNjZXNzJykgJiYgaXNzZXQoJGdhbGxleUlkKSAmJiAk
Z2FsbGV5SWQpIHsKIAkJCQlWYWxpZGF0aW9uOjpyZWRpcmVjdExvZ2luKCk7CiAJCQl9CiAKIAkJ
CS8vIGJ5cGFzcyBhbGwgdmFsaWRhdGlvbiBpZiBzdWJzY3JpcHRpb24gYmFzZWQgb24gZG9tYWlu
IG9yIGlwIGlzIHZhbGlkCiAJCQkvLyBvciBpZiB0aGUgdXNlciBpcyBqdXN0IHJlcXVlc3Rpbmcg
dGhlIGFic3RyYWN0CiAJCQlpZiAoICghJGlzU3Vic2NyaWJlZERvbWFpbiAmJiAkc3Vic2NyaXB0
aW9uUmVxdWlyZWQpICYmCi0JCQkgICAgIChpc3NldCgkZ2FsbGV5SWQpICYmICRnYWxsZXlJZCE9
MCkgKSB7CisJCQkgICAgIChpc3NldCgkZ2FsbGV5SWQpICYmICRnYWxsZXlJZCkgKSB7CiAKIAkJ
CQkvLyBTdWJzY3JpcHRpb24gQWNjZXNzCiAJCQkJJHN1YnNjcmliZWRVc2VyID0gSXNzdWVBY3Rp
b246OnN1YnNjcmliZWRVc2VyKCRqb3VybmFsLCAkaXNzdWUtPmdldElkKCksICRhcnRpY2xlSWQp
OwpAQCAtNDgzLDkgKzQ4Myw5IEBACiAJCQkJCQlpZiAoICRwYXltZW50TWFuYWdlci0+b25seVBk
ZkVuYWJsZWQoKSApIHsKIAkJCQkJCQkkZ2FsbGV5REFPID0mIERBT1JlZ2lzdHJ5OjpnZXREQU8o
J0FydGljbGVHYWxsZXlEQU8nKTsKIAkJCQkJCQlpZiAoJGpvdXJuYWwtPmdldFNldHRpbmcoJ2Vu
YWJsZVB1YmxpY0dhbGxleUlkJykpIHsKLQkJCQkJCQkJJGdhbGxleSA9JiAkZ2FsbGV5REFPLT5n
ZXRHYWxsZXkoJGdhbGxleUlkLCAkYXJ0aWNsZUlkKTsKLQkJCQkJCQl9IGVsc2UgewogCQkJCQkJ
CQkkZ2FsbGV5ID0mICRnYWxsZXlEQU8tPmdldEdhbGxleUJ5QmVzdEdhbGxleUlkKCRnYWxsZXlJ
ZCwgJGFydGljbGVJZCk7CisJCQkJCQkJfSBlbHNlIHsKKwkJCQkJCQkJJGdhbGxleSA9JiAkZ2Fs
bGV5REFPLT5nZXRHYWxsZXkoJGdhbGxleUlkLCAkYXJ0aWNsZUlkKTsKIAkJCQkJCQl9CiAJCQkJ
CQkJaWYgKCAkZ2FsbGV5ICYmICEkZ2FsbGV5LT5pc1BkZkdhbGxleSgpICkgewogCQkJCQkJCQkk
dGhpcy0+am91cm5hbCA9JiAkam91cm5hbDsK
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3443</attachid>
            <date>2011-03-01 22:50:00 -0800</date>
            <delta_ts>2011-03-01 22:50:36 -0800</delta_ts>
            <desc>Patch against OJS 2.3.4</desc>
            <filename>6458.diff</filename>
            <type>text/plain</type>
            <size>1950</size>
            <attacher>michael.pkp</attacher>
            
              <data encoding="base64">LS0tIGEvcGFnZXMvYXJ0aWNsZS9BcnRpY2xlSGFuZGxlci5pbmMucGhwCisrKyBiL3BhZ2VzL2Fy
dGljbGUvQXJ0aWNsZUhhbmRsZXIuaW5jLnBocApAQCAtNDE0LDcgKzQxNCw3IEBAIGNsYXNzIEFy
dGljbGVIYW5kbGVyIGV4dGVuZHMgSGFuZGxlciB7CiAJICogQHNlZSBsaWIvcGtwL2NsYXNzZXMv
aGFuZGxlci9QS1BIYW5kbGVyI3ZhbGlkYXRlKCkKIAkgKiBAcGFyYW0gJHJlcXVlc3QgUmVxdWVz
dAogCSAqIEBwYXJhbSAkYXJ0aWNsZUlkIGludGVnZXIKLQkgKiBAcGFyYW0gJGdhbGxleUlkIGlu
dGVnZXIKKwkgKiBAcGFyYW0gJGdhbGxleUlkIGludCBvciBzdHJpbmcKIAkgKi8KIAlmdW5jdGlv
biB2YWxpZGF0ZSgmJHJlcXVlc3QsICRhcnRpY2xlSWQsICRnYWxsZXlJZCA9IG51bGwpIHsKIAkJ
JHJvdXRlciA9JiAkcmVxdWVzdC0+Z2V0Um91dGVyKCk7CkBAIC00NjEsMTQgKzQ2MSwxNCBAQCBj
bGFzcyBBcnRpY2xlSGFuZGxlciBleHRlbmRzIEhhbmRsZXIgewogCQkJJGlzU3Vic2NyaWJlZERv
bWFpbiA9IElzc3VlQWN0aW9uOjpzdWJzY3JpYmVkRG9tYWluKCRqb3VybmFsLCAkaXNzdWUtPmdl
dElkKCksICRhcnRpY2xlSWQpOwoKIAkJCS8vIENoZWNrIGlmIGxvZ2luIGlzIHJlcXVpcmVkIGZv
ciB2aWV3aW5nLgotCQkJaWYgKCEkaXNTdWJzY3JpYmVkRG9tYWluICYmICFWYWxpZGF0aW9uOjpp
c0xvZ2dlZEluKCkgJiYgJGpvdXJuYWwtPmdldFNldHRpbmcoJ3Jlc3RyaWN0QXJ0aWNsZUFjY2Vz
cycpICYmIGlzc2V0KCRnYWxsZXlJZCkgJiYgJGdhbGxleUlkICE9IDApIHsKKwkJCWlmICghJGlz
U3Vic2NyaWJlZERvbWFpbiAmJiAhVmFsaWRhdGlvbjo6aXNMb2dnZWRJbigpICYmICRqb3VybmFs
LT5nZXRTZXR0aW5nKCdyZXN0cmljdEFydGljbGVBY2Nlc3MnKSAmJiBpc3NldCgkZ2FsbGV5SWQp
ICYmICRnYWxsZXlJZCkgewogCQkJCVZhbGlkYXRpb246OnJlZGlyZWN0TG9naW4oKTsKIAkJCX0K
CiAJCQkvLyBieXBhc3MgYWxsIHZhbGlkYXRpb24gaWYgc3Vic2NyaXB0aW9uIGJhc2VkIG9uIGRv
bWFpbiBvciBpcCBpcyB2YWxpZAogCQkJLy8gb3IgaWYgdGhlIHVzZXIgaXMganVzdCByZXF1ZXN0
aW5nIHRoZSBhYnN0cmFjdAogCQkJaWYgKCAoISRpc1N1YnNjcmliZWREb21haW4gJiYgJHN1YnNj
cmlwdGlvblJlcXVpcmVkKSAmJgotCQkJICAgICAoaXNzZXQoJGdhbGxleUlkKSAmJiAkZ2FsbGV5
SWQhPTApICkgeworCQkJICAgICAoaXNzZXQoJGdhbGxleUlkKSAmJiAkZ2FsbGV5SWQpICkgewoK
IAkJCQkvLyBTdWJzY3JpcHRpb24gQWNjZXNzCiAJCQkJJHN1YnNjcmliZWRVc2VyID0gSXNzdWVB
Y3Rpb246OnN1YnNjcmliZWRVc2VyKCRqb3VybmFsLCAkaXNzdWUtPmdldElkKCksICRhcnRpY2xl
SWQpOwpAQCAtNDg0LDkgKzQ4NCw5IEBAIGNsYXNzIEFydGljbGVIYW5kbGVyIGV4dGVuZHMgSGFu
ZGxlciB7CiAJCQkJCQlpZiAoICRwYXltZW50TWFuYWdlci0+b25seVBkZkVuYWJsZWQoKSApIHsK
IAkJCQkJCQkkZ2FsbGV5RGFvID0mIERBT1JlZ2lzdHJ5OjpnZXREQU8oJ0FydGljbGVHYWxsZXlE
QU8nKTsKIAkJCQkJCQlpZiAoJGpvdXJuYWwtPmdldFNldHRpbmcoJ2VuYWJsZVB1YmxpY0dhbGxl
eUlkJykpIHsKLQkJCQkJCQkJJGdhbGxleSA9JiAkZ2FsbGV5RGFvLT5nZXRHYWxsZXkoJGdhbGxl
eUlkLCAkYXJ0aWNsZUlkKTsKLQkJCQkJCQl9IGVsc2UgewogCQkJCQkJCQkkZ2FsbGV5ID0mICRn
YWxsZXlEYW8tPmdldEdhbGxleUJ5QmVzdEdhbGxleUlkKCRnYWxsZXlJZCwgJGFydGljbGVJZCk7
CisJCQkJCQkJfSBlbHNlIHsKKwkJCQkJCQkJJGdhbGxleSA9JiAkZ2FsbGV5RGFvLT5nZXRHYWxs
ZXkoJGdhbGxleUlkLCAkYXJ0aWNsZUlkKTsKIAkJCQkJCQl9CiAJCQkJCQkJaWYgKCAkZ2FsbGV5
ICYmICEkZ2FsbGV5LT5pc1BkZkdhbGxleSgpICkgewogCQkJCQkJCQkkdGhpcy0+am91cm5hbCA9
JiAkam91cm5hbDsK
</data>

          </attachment>
      

    </bug>

</bugzilla>