Since it is insecure to send authentication credentials via an unencrypted connection, I patched my installation of phpmyfaq 2.5.2 to only show the loginfields if connected via HTTPS. If you are connected via HTTP only, you will only see a link, which points to the HTTPS version of the current view.
I attached a patch, just for the case anybody is interested.
only show login fields when connecting via HTTPS
Moderator: Thorsten
only show login fields when connecting via HTTPS
You do not have the required permissions to view the files attached to this post.
Re: only show login fields when connecting via HTTPS
Hi,
nice patch... but most people don't have the chance to use https... I could add this as option, what do you think?
bye
Thorsten
nice patch... but most people don't have the chance to use https... I could add this as option, what do you think?
bye
Thorsten
phpMyFAQ Maintainer and Lead Developer
amazon.de Wishlist
amazon.de Wishlist
Re: only show login fields when connecting via HTTPS
Would be nice to have this in the next version.
I didn't know there are still people out there who can't use HTTPS. That's quite strange, but they probably have accounts at some strange webhosters.
I also would make this patch complete, but I don't have time at the moment to make it good enough.
I didn't know there are still people out there who can't use HTTPS. That's quite strange, but they probably have accounts at some strange webhosters.
I also would make this patch complete, but I don't have time at the moment to make it good enough.
Re: only show login fields when connecting via HTTPS
Hmm, OK, I improved my patch. (Seems I found time for this after all. ) This may need some improvement, but it seems to work. The patch contains the german and englisch translations, the patched initial sql-table files and has support for the configuration menu.
You do not have the required permissions to view the files attached to this post.
Re: only show login fields when connecting via HTTPS
Hi,
thanks for the patch, it's implemented in phpMyFAQ 2.6.0-alpha. Is it okay to add your name in the changelog?
bye
Thorsten
thanks for the patch, it's implemented in phpMyFAQ 2.6.0-alpha. Is it okay to add your name in the changelog?
bye
Thorsten
phpMyFAQ Maintainer and Lead Developer
amazon.de Wishlist
amazon.de Wishlist
Re: only show login fields when connecting via HTTPS
Yes, of course you can add my name (Tobias Hommel) to the changelog.
Re: only show login fields when connecting via HTTPS
Hi,
released to public in 2.6.0-alpha.
bye
Thorsten
released to public in 2.6.0-alpha.
bye
Thorsten
phpMyFAQ Maintainer and Lead Developer
amazon.de Wishlist
amazon.de Wishlist