Login Form

#170 – Un-Masking Bid Usernames again

Posted in ‘BF Auction’
This is a public ticket. Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.
Saturday, 22 March 2014 21:05 AEDT
disc
Joomla! version: 2.5.14

With BF Auction Plus 1.5.4 there seems to be a new issue un-masking usernames.
Ticket #16 gives a solution for all views but does not help for the bid view.
Seems that the id"highBidder" used in the related <div> is defined somewhere and is relevant for displaying the username, independently what the following php-code says.

<td class="bfauction_plusDetails">
<div id="highBidder" style="float: left; text-align: left;" /></div>
<?php
if($this->bfauction_plus->highBidder == $user->username){
if($this->lastbid->maxbid > 0){
echo ' ('.$bfcurrency.''.$this->lastbid->maxbid.')';
}
}
?>

In 1.5.4 there is also no definition in ...controllers/bid.php as described in ticket #16:
Then you'd need to edit /components/com_bfauction_pro/controllers/bid.php, around line 86
$highBidder = substr($highBidder, 0, 1).'******'.substr($highBidder, -1);
 
Saturday, 22 March 2014 21:42 AEDT 10'
Tim
Everything Bundle, BF Quiz Plus 3 Years, BF Survey 12 Months
The high bidder is updated via AJAX, and the code that you are looking for is in the luCurrentBid function in /components/com_bfauction_plus/controller.php

//around line 1378
if($highBidder == $user->username){
$highBidder = JText::_('COM_BFAUCTIONPLUS_YOU_ARE_CURRENT_BIDDER');
}else{
$highBidder = substr($highBidder, 0, 1).'******'.substr($highBidder, -1);
}

regards

Tim
Follow us on twitter http://twitter.com/tamlynsoftware
Saturday, 22 March 2014 23:29 AEDT
disc
Thanks, Tim. That´s it.
Closing this one.
 
This ticket is closed, therefore read-only. You can no longer reply to it. If you need to provide more information, please open a new ticket and mention this ticket's number.
Go to top