Hacker Poesy
  • FAQ
  • Login
  • Public

    • Public
    • Groups
    • Recent tags
    • Popular
    • Directory

Conversation:

Notices

  1. maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 05:22:20 EST maiyannah maiyannah
    Remote profile options...
    • verius
    @verius "but maybe there's a less stressful way for the server."

    Almost makes it sound like we were proposing a new API for some sort of reason ;)
    Saturday, 24-Dec-2016 05:22:20 EST from community.highlandarrow.com permalink
    • maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 05:22:51 EST maiyannah maiyannah
      Remote profile options...
      • verius
      @verius More seriously, that's the one *reliable* way to prove that the user is authenticated and its THAT user whom is logged in.
      Saturday, 24-Dec-2016 05:22:51 EST permalink
    • maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 05:26:10 EST maiyannah maiyannah
      Remote profile options...
      • verius
      • Constance Variable
      @lambadalambda @verius That'll work at the time you're sending credentials.  It won't work later.  But it may be okay for what Verius is doing.
      Saturday, 24-Dec-2016 05:26:10 EST permalink
    • maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 05:30:43 EST maiyannah maiyannah
      Remote profile options...
      • verius
      @verius Specifically, just so you know, the problem there is that the user login information isn't persisted at all for security reasons, so it has no real way to know the credentials are valid unless you're already logged in, or you're logging in _at that time_. It's probably still a good idea to prevent shifting-style attacks to make sure it's the user they say th…
      Saturday, 24-Dec-2016 05:30:43 EST permalink

      Attachments

      1. maiyannah-20161224-ostatus-zzbr.html
    • maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 05:32:08 EST maiyannah maiyannah
      Remote profile options...
      • verius
      @verius The problem with situations where you're already logged in that the session handling in postActiv right now is really shit and drops sessions randomly. and you can actually end up in situations where you're still logged in, but it doesn't recognize the session so it will return a client error 404 (which is an incorrect error code in this instance, but I'm not the one that wrote that code...)
      Saturday, 24-Dec-2016 05:32:08 EST permalink
    • maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 05:37:10 EST maiyannah maiyannah
      Remote profile options...
      • verius
      @verius Haha, yeah that works.
      Saturday, 24-Dec-2016 05:37:10 EST permalink
    • maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 06:01:07 EST maiyannah maiyannah
      Remote profile options...
      • verius
      @verius yeaaaaaaaaaaah

      And it should

      It doesnt though
      Saturday, 24-Dec-2016 06:01:07 EST permalink
    • maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 06:05:47 EST maiyannah maiyannah
      Remote profile options...
      • verius
      @verius Well it's easy enough to fix that error code to be a 401 at least.  I'll do that next I'm at my computer properly.
      Saturday, 24-Dec-2016 06:05:47 EST permalink
    • maiyannah (maiyannah)'s status on Saturday, 24-Dec-2016 06:09:08 EST maiyannah maiyannah
      Remote profile options...
      • verius
      @verius Yeah.  Well, I won't want to forget it so I'll grab that one ASAP.
      Saturday, 24-Dec-2016 06:09:08 EST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • Privacy
  • Source
  • Version
  • Contact

Hacker Poesy is a GNU social hub. It runs version 1.1.3-beta3, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Hacker Poesy content and data are available under the Creative Commons Attribution 3.0 license.

Switch to mobile site layout.