Zen Cart Logo
Forums / Bug Reports / *[Fixed 1.6.0] password_forgotten generates log file

*[Fixed 1.6.0] password_forgotten generates log file

Locked

Views: 5,680

Results 1 to 5 of 5
This thread is locked. New replies are disabled.
28 Sep 2012, 1:32 PM
#1
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,100
Plugin Contributions:
56

*[Fixed 1.6.0] password_forgotten generates log file

Running "vanilla" v1.5.1 on localhost via XAMPP:

Server Host: localhost (127.0.0.1)       	Database Host: localhost (127.0.0.1)
Server OS: Windows NT xxxx 6.1 build 7601 (Windows 7 Ultimate Edition Service Pack 1) i586    	Database: MySQL 5.5.16
Server Date: 09/28/2012 15:24:10   	Database Date: 09/28/2012 09:24:10
Server Up Time: Unsupported 	HTTP Server: Apache/2.2.21 (Win32) mod_ssl/2.2.21 OpenSSL/1.0.0e PHP/5.3.8 mod_perl/2.0.4 Perl/v5.10.1
PHP Version: 5.3.8 (Zend: 2.3.0)   PHP Memory Limit: 128M 	PHP Safe Mode: Off
PHP File Uploads: On    Max Size: 128M 	POST Max Size: 8M
Database Data Size: 898 kB 	Database Index Size: 471 kB

When I use the password_forgotten page, a log-file is generated with a number of the following entries:

[28-Sep-2012 15:19:25] PHP Warning:  sha1_file(/includes/configure.php) [<a href='function.sha1-file'>function.sha1-file</a>]: failed to open stream: No such file or directory in C:\xampp\htdocs\mywebsite\includes\functions\password_funcs.php on line 118

Please let me know what other information will be helpful.

29 Sep 2012, 9:38 PM
#2
lhungil avatar

lhungil

Totally Zenned

Join Date:
Feb 2012
Location:
mostly harmless
Posts:
1,818
Plugin Contributions:
4

Re: *[Fixed 1.6.0] password_forgotten generates log file

Some changes were made in 1.5.1 to the password forgotten behavior. It now uses a different method of generating passwords. My test environment resides on a site root, so I did not notice this issue.

Try changing functions_password_funcs.php (starting at line 116):

  if (strlen($entropy) < 16)
  {
[B]     $entropy = sha1_file('/includes/configure.php');[/B]
    $entropy .= microtime() . mt_rand() . $seed;
    //echo "USING FALLBACK" . "<br>";
  }

To:

  if (strlen($entropy) < 16)
  {
[B]     $entropy = sha1_file(DIR_FS_CATALOG . DIR_WS_INCLUDES . 'configure.php');[/B]
    $entropy .= microtime() . mt_rand() . $seed;
    //echo "USING FALLBACK" . "<br>";
  }

Let me know if this worked in your environment :)

30 Sep 2012, 10:28 AM
#3
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,100
Plugin Contributions:
56

Re: *[Fixed 1.6.0] password_forgotten generates log file

Thanks, lhungil. I was so focused on the fact that it was a sha1_file call that I totally missed that the problem was actually a "missing" file. Your fix worked like a charm!

30 Sep 2012, 7:39 PM
#4
lhungil avatar

lhungil

Totally Zenned

Join Date:
Feb 2012
Location:
mostly harmless
Posts:
1,818
Plugin Contributions:
4

Re: *[Fixed 1.6.0] password_forgotten generates log file

Thank You.