121
skenow
Re: Proposal: Towards A Sustainable Open Source Project
  • 2007/10/24 23:45

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Clarification, please, DJ - is this a response to the thread by Crip, or is it a separate proposal? Is this put forward as your proposal, or as one of the council's?



122
skenow
Re: different uploads directory
  • 2007/10/21 22:06

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Proceed with caution!

include/common.php => around line 137:

define("XOOPS_UPLOAD_URL"XOOPS_URL."/uploads");


You can even move a few other folders, if you were inclined to do so



123
skenow
Re: Testing Xoops Total 2.0.18 Package.
  • 2007/10/21 22:00

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Quote:

script_fu wrote:
So the code is secure. What skenow is trying to say is be careful do not give anyone webmaster status thats not trusted.


Bingo! Understand the power of custom blocks before granting access to anyone. (Hint: do a search for 'fork bomb')

Most of this is off-topic, but relevant to the discussion at hand - what features to add to a core distribution and which ones should not be added.

Webmaster access should be reserved for the site administrator only for system administration, not day-to-day access. As a rule, one of the first things I do with a new install is create a new group (call it what you want, and even rename Webmasters, like I do) for day-to-day maintenance and give them access to everything except:

Blocks
Groups
Preferences

I also cautiously add module administration for most modules - but, never for Protector.

Nice to see some interest in testing new release candidates, though



124
skenow
Re: A Problem stayin logged in
  • 2007/10/21 12:58

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Administration menu > System Admin > Preferences > General Settings :: Use custom session



125
skenow
Re: Testing Xoops Total 2.0.18 Package.
  • 2007/10/21 12:43

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Quote:

script_fu wrote:
Quote:

skenow wrote:
I would caution against allowing editing blocks by anyone except an admin, unless you can restrict by group and disallow HTML and PHP blocks. Nor should the frontend editor allow changing of block types. Please consider the security of such actions.


Huh?

Are you aware of an issue with the edit blocks code? The edit blocks code can only be used by admin no one else.


Only if you set permissions correctly.

From Securing your site

Quote:

13. Never give admin rights to anyone, especially to the XOOPS blocks admin.



126
skenow
Re: A Problem stayin logged in
  • 2007/10/20 23:48

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Have you tried using custom sessions? Or, the other suggestion in the release notes?



127
skenow
Re: Testing Xoops Total 2.0.18 Package.
  • 2007/10/20 22:20

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


I would caution against allowing editing blocks by anyone except an admin, unless you can restrict by group and disallow HTML and PHP blocks. Nor should the frontend editor allow changing of block types. Please consider the security of such actions.



128
skenow
Re: Not Safe or Recommended Module List! Are they Hackable?
  • 2007/10/19 2:40

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Quote:

script_fu wrote:
Yep the lost categories... Whats up with that? It shocked me when I found them! Where did they come from? lol

I do remember going thru what was there years ago. Never gave it any thought after that. I always turn that block off in my XOOPS sites its a waste of time and link directly to the cat.


Something to consider as the site is 'redesigned' (repurposed might be closer to the real need) - what to put on the main page?

Recent News - definitely, but need to look at the categories and how articles gain the spotlight. My perspective - I come here for the news about XOOPS and its development, and examples of how XOOPS is used. More important than the latest forum post is the information about XOOPS and what is relevant. From a marketing perspective, the recent news and spotlight does more to send people away than it does to attract.

Getting started - what do I need, where do I get it and what do I do next?

Navigation to the other things I might need - support, documentation, modules and themes. K.I.S.S.



129
skenow
Re: Xoops Web Site Stats: Installing Slimstat
  • 2007/10/19 2:26

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17





130
skenow
Re: Xoops Web Site Stats: Installing Slimstat
  • 2007/10/19 0:19

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Link not working at the time of this post - in fact, the entire site is down: 403 Forbidden




TopTop
« 1 ... 10 11 12 (13) 14 15 16 ... 86 »



Login

Who's Online

163 user(s) are online (89 user(s) are browsing Support Forums)


Members: 0


Guests: 163


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits