discuss AT lists.opennicproject.org
Subject: Discuss mailing list
List archive
- From: Martin C <martin AT mchomenet.com>
- To: discuss AT lists.opennicproject.org
- Subject: Re: [opennic-discuss] User and Domain Management System
- Date: Wed, 30 May 2012 09:38:32 +1000
A side note about the confirmation mails: maybe you should check if theThis is why I am having a public test, to get others to try it out and go through scenarios that I might not have thought of.
username that's being confirmed actually exists?
if i enter confirm.php?username=whateveriwant, it says the username has
been registered...
I don't know what kind of checks you have, but it is at the very leastI have not heard of that particular practice myself, so I'll take your word for it. I figured users would only try to activate accounts that they themselves have registered. At most, it gets some spammers hopes up until they realise they need to register and confirm a real account before they can do anything.
bad practice to say a username that hasn't been requested is registered.
But I'll implement some error checking in the next revision to fix this.
at the very worst, you could end up with a hell of a lot of databaseNothing is changed within the database if you try to confirm a username that doesn't actually exist in there yet.
pollution.
If you are referring to database accesses, then it only does one at the moment, rather than the two it would need to verify the username and then activate the account.
logging in obviously doesnt work as there's no password for the user,At the user registration page it says all fields must be at least 5 characters long, this check is done twice. The software will definitely not allow a non-existent user account to be activated and then permit them an empty or NULL password, otherwise yes, the database would get pollution. That would be A Bad Thing (tm).
and i'm assuming your script checks empty passwords, so that's good :)
Thanks for giving it a look-see. I'll implement the check for a non-existent account this morning. Good catch.
Martin.
- Re: [opennic-discuss] User and Domain Management System, (continued)
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/26/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/26/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/28/2012
- Re: [opennic-discuss] User and Domain Management System, Amrit Panesar, 05/29/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/29/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/28/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/26/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/26/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/28/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/29/2012
- Re: [opennic-discuss] User and Domain Management System, Peter Green, 05/29/2012
- Re: [opennic-discuss] User and Domain Management System, Bjorn Peeters, 05/29/2012
- Re: [opennic-discuss] User and Domain Management System, Martin C, 05/29/2012
- Re: [opennic-discuss] User and Domain Management System, Bjorn Peeters, 05/29/2012
- Re: [opennic-discuss] User and Domain Management System, Peter Green, 05/29/2012
Archive powered by MHonArc 2.6.19.