FUDforum
Fast Uncompromising Discussions. FUDforum will get your users talking.

Home » FUDforum Development » FUDforum 3.0+ » Session Referrer Check not at login?
Show: Today's Messages :: Polls :: Message Navigator
Switch to threaded view of this topic Create a new topic Submit Reply
Session Referrer Check not at login? [message #30212] Sat, 11 February 2006 22:55 Go to next message
Xonk is currently offline  Xonk   Germany
Messages: 67
Registered: March 2004
Karma: 0
Member
Hi,

one suggestion: Disable the referrer Check at login.
The problem is, when a user starts the forum with 'url.de', and uses the fast-login via the homepage, the user will be redirect to 'www.url.de' and the session is killed. So the user have to login two times.

Greets,

Sven
Re: Session Referrer Check not at login? [message #30214 is a reply to message #30212] Sat, 11 February 2006 22:58 Go to previous messageGo to next message
Ilia is currently offline  Ilia   Canada
Messages: 13241
Registered: January 2002
Karma: 0
Senior Member
Administrator
Core Developer
Referer check is something you can disable yourself via the forum's settings.

FUDforum Core Developer
Re: Session Referrer Check not at login? [message #30217 is a reply to message #30214] Sat, 11 February 2006 23:13 Go to previous messageGo to next message
Xonk is currently offline  Xonk   Germany
Messages: 67
Registered: March 2004
Karma: 0
Member
Thanks for this fast answer Smile.

Ok, I can disable it, but I think, that this feature is useful to prevent session-takeover when a user publish a link with his session-ID (and don't uses cookies). Or is it wrong, what I'm thinking about the referrer check?

When it is correct, a additional control to diable the check at login when basically enabled, would be nice.

Greets,

Sven
Re: Session Referrer Check not at login? [message #30218 is a reply to message #30217] Sat, 11 February 2006 23:20 Go to previous messageGo to next message
Ilia is currently offline  Ilia   Canada
Messages: 13241
Registered: January 2002
Karma: 0
Senior Member
Administrator
Core Developer
If you want to keep the check, I'd suggest a simple mod_rewrite rule that would redirec the users from foo.com to www.foo.com.

FUDforum Core Developer
Re: Session Referrer Check not at login? [message #30219 is a reply to message #30218] Sat, 11 February 2006 23:46 Go to previous message
Xonk is currently offline  Xonk   Germany
Messages: 67
Registered: March 2004
Karma: 0
Member
Thanks, that's an idea.
  Switch to threaded view of this topic Create a new topic Submit Reply
Previous Topic: Realy slow
Next Topic: new to fud forum ?
Goto Forum:
  

-=] Back to Top [=-
[ Syndicate this forum (XML) ] [ RSS ]

Current Time: Sun Nov 10 13:14:44 GMT 2024

Total time taken to generate the page: 0.02309 seconds