/header.html About HyperNews
Next-in-Thread Next Message

get is secured 

Keywords: get security
Forum: HyperNews Security
Re: Securing get (Jon Tara)
Date: 1996, Feb 18
From: Daniel M LaLiberte <liberte>

Even though 'get' is not in the SECURED directory, it is secured by the presense of the .htaccess file in the HyperNews directory, as you noted.

We did this intentionally so that you would not have to change the advertised URLs of documents even though you changed the security of them. I might want to post on a newsgroup about a HyperNews response I added about some related subject. The other programs, such as edit-member.pl, are not typically advertised, or only locally referenced. In the setup-form.pl script, it says that making reading secured effectively secures everything else too. So everything is working as planned.

But you want something different - public joining. This is reasonable. If joining is the one and only special case, I could probably add a special check for this situation. Or I could make it more general by checking whether there are any public functions.

You may have noticed that 'get' is also available in the SECURED directory, along with all the other public functions. So you could just remove 'get' (and thread) from the HyperNews directory.

Another point that should be raised here is the 'get' is never secured with manual_security. I don't want to put password in URLs.

Next-in-Thread Next Message
Inline: 1 All Outline: 1 2 All

1 Feedback: Here's how to do it for Netscape by jtara@stockclub.com, 1996, Feb 18

Add to: "get is secured"

Members Subscribe Admin Mode
Show Frames Help


Installation Topics:
  • Creating Base Articles, also called Forums.
  • Security Issues regarding HyperNews
  • Bidirectional E-mail gateway

    Earn money with Scour!
    Google
     
    Web www.HyperNews.org
    Earn money with Scour!