Automatic logon broken

This is the place to ask if you have any issues with our forum system. These include questions about your account, PM's, login trouble, etc.

Re: Automatic logon broken

Postby broadblues » Wed Dec 05, 2018 5:32 pm

MichaelMerkel wrote:it seems the cookie is not set?


A cookie *must* be set else, you could not log in at all.

i removed my old one and there is no new one stored.

regards...
michael


It could have changed to temporary cookie or one with a shorter expiery time perhaps?
User avatar
broadblues
AmigaOS Core Developer
AmigaOS Core Developer
 
Posts: 551
Joined: Sat Jun 18, 2011 3:40 am
Location: Portsmouth, UK

Re: Automatic logon broken

Postby Raziel » Wed Dec 05, 2018 6:01 pm

There is no cookie.

I just checked again with Odyssey cookie list and there is absolutely nothing regarding hyperion-entertainment.biz.

I can log on, but as soon as i leave the site and come back immediately i have to log in again.

There are hyperion cookies in the sql .db file, but they don't come up in Odysseys cookie list
If slaughterhouses had glass walls, everyone would be a vegetarian. ~ Sir Paul McCartney
-
Did everything just taste purple for a second? ~ Philip J. Fry
-
Ain't got no cash, ain't got no style, ladies vomit when I smile. ~ Dr. John Zoidberg
User avatar
Raziel
 
Posts: 864
Joined: Sat Jun 18, 2011 5:00 pm
Location: A haunted Castle somewhere in the Bavarian Mountains

Re: Automatic logon broken

Postby broadblues » Wed Dec 05, 2018 7:53 pm

Hmmm okay testing a bit more, it seems the session ID to enable login is being sent in the URL. Side stepping the need for a temporary cookie.

The reason I could post without logging in was that I used URL completion and effectively preserved the session ID< which hadn't expired yet.

Ugh. That feels a fraction insecure! Were I to post the URL you might be able to login as me!
User avatar
broadblues
AmigaOS Core Developer
AmigaOS Core Developer
 
Posts: 551
Joined: Sat Jun 18, 2011 3:40 am
Location: Portsmouth, UK

Re: Automatic logon broken

Postby Raziel » Wed Dec 05, 2018 8:10 pm

broadblues wrote:Hmmm okay testing a bit more, it seems the session ID to enable login is being sent in the URL. Side stepping the need for a temporary cookie.

The reason I could post without logging in was that I used URL completion and effectively preserved the session ID< which hadn't expired yet.

Ugh. That feels a fraction insecure! Were I to post the URL you might be able to login as me!

Ouch...
Hopefully some of the maintainers are monitoring this
If slaughterhouses had glass walls, everyone would be a vegetarian. ~ Sir Paul McCartney
-
Did everything just taste purple for a second? ~ Philip J. Fry
-
Ain't got no cash, ain't got no style, ladies vomit when I smile. ~ Dr. John Zoidberg
User avatar
Raziel
 
Posts: 864
Joined: Sat Jun 18, 2011 5:00 pm
Location: A haunted Castle somewhere in the Bavarian Mountains

Re: Automatic logon broken

Postby ssolie » Thu Dec 06, 2018 10:09 pm

Raziel wrote:Hopefully some of the maintainers are monitoring this

Try emailing webmaster@hyperion-entertainment.com
AmigaOS Development Team Lead
Be authentic. Get AmigaOS.
User avatar
ssolie
AmigaOS Core Developer
AmigaOS Core Developer
 
Posts: 1009
Joined: Mon Dec 20, 2010 9:51 pm
Location: Canada

Re: Automatic logon broken

Postby Cyborg » Sun Dec 09, 2018 11:18 pm

All requests are now redirected to use the .com domain. This broke the cookie settings, which were still using .biz. Fixed now.
User avatar
Cyborg
AmigaOS Core Developer
AmigaOS Core Developer
 
Posts: 53
Joined: Wed Feb 16, 2011 2:29 pm

Re: Automatic logon broken

Postby tonyw » Mon Dec 10, 2018 12:21 am

Yes, fixed now, thanks, Costel.
cheers
tony
User avatar
tonyw
AmigaOS Core Developer
AmigaOS Core Developer
 
Posts: 1332
Joined: Wed Mar 09, 2011 2:36 pm
Location: Sydney, Australia

Previous

Return to Forum Questions

Who is online

Users browsing this forum: No registered users and 2 guests