| Next-in-Thread | Next Message |
|
Even though 'get' is not in the SECURED directory, it is secured by the presense of the .htaccess file in the HyperNews directory, as you noted. We did this intentionally so that you would not have to change the advertised URLs of documents even though you changed the security of them. I might want to post on a newsgroup about a HyperNews response I added about some related subject. The other programs, such as edit-member.pl, are not typically advertised, or only locally referenced. In the setup-form.pl script, it says that making reading secured effectively secures everything else too. So everything is working as planned. But you want something different - public joining. This is reasonable. If joining is the one and only special case, I could probably add a special check for this situation. Or I could make it more general by checking whether there are any public functions. You may have noticed that 'get' is also available in the SECURED directory, along with all the other public functions. So you could just remove 'get' (and thread) from the HyperNews directory. Another point that should be raised here is the 'get' is never secured with manual_security. I don't want to put password in URLs. |
| Next-in-Thread | Next Message |
| Inline: | 1 | All | Outline: | 1 | 2 | All |
| Add |
to: |
| Members | Subscribe | Admin Mode |
| Show Frames | Help |
|
|