28, May 2012

Version 0.9 released - webmaster forum

 
Webdigity webmaster forums
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  PhP  >  Php User Class
Topic: Version 0.9 released
« previous next »
Pages: [1] Print
Instabuck - The easy way to sell digital products online

Author Topic: Version 0.9 released  (Read 2116 times)
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5799
46391 credits
Members referred : 3



« on: Oct 29, 2007, 10:35:14 am »

Just wanted to let you know that a new version of php user class has just been released. The new version fixes one small bug, and adds a few features.

For more information check the class changelog.

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Bill Cosby is my Father
*
Posts: 4
24 credits
Members referred : 0


« Reply #1 on: Nov 07, 2007, 04:25:57 pm »

I had good results testing the example files of the new version. Smiley You are doing a great job!

By the way, maybe you could do some little tutorial, so we can learn all the features that can be used with it. I understand that not all the features are covered on the example files.

Thank you!
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5799
46391 credits
Members referred : 3



« Reply #2 on: Nov 07, 2007, 09:55:47 pm »

I am afraid I have no time for this at this point, as I am going to army in 5 days Smiley

But I guess with a little experimenting and reading my comments at the class files you can see all the possibilities of the class.

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5799
46391 credits
Members referred : 3



« Reply #3 on: Nov 09, 2007, 10:13:30 am »

I've just released version 0.91 which fixes a small bug in the user logout function.

If you are using 0.9 please update to the new version.

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Just another rainy day
*
Posts: 1
6 credits
Members referred : 0


« Reply #4 on: Nov 23, 2007, 03:26:50 am »

Overall I think you have a nice class which could be especially useful for newer programmers.  Your example pages however contain the often used flaw of setting a form action attribute (or a redirect) to $_SERVER['PHP_SELF'] which is a well documented XSS vulnerability.  As your class is for implementing security, leaving XSS in the examples is probably not wise, considering the general audience.

Simply Google for XSS $_SERVER['PHP_SELF']
http://xforce.iss.net/xforce/xfdb/26518

Similarly the lack of input validation in the examples and in the class could lead to various problems.

Also, I would remove the inline SQL in favor of parameterized SQL (for example: http://www.expertsrt.net/main/components/com_mambowiki/index.php?title=PHP_MySql_Prepared_Statements_Library) and the more secure mysqli functions.

While you take precautions to prevent common SQL injection, you might want to consider some unexpected injections which can occur, such as those published here:
http://mordred.niama.net/blog/?p=121

Again,pretty darn good start, but a few tweaks could lead to something bullet-proof and very useful to the newer developers.  Possibly something like Reform. http://www.owasp.org/index.php/Category:OWASP_Encoding_Project

Best regards,
Rod





 
Google dot what?
*
Posts: 2
12 credits
Members referred : 0


« Reply #5 on: Nov 29, 2007, 12:39:43 am »

Hello, thanks so much for this class!  It's working brilliantly.  I'm on version .91, but I still am experiencing the bug that you said you squashed, the logout with cookies.  If I check the Remember Me? box, I can not logout without manually removing the cookie... I'd appreciate any input you might have.  Thanks!
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5799
46391 credits
Members referred : 3



« Reply #6 on: Dec 07, 2007, 09:41:33 am »

Hi fellas, and thanks for your input. I will try to check those problems but as I am in the army now I am in lack of time.

I would really appreciate if someone can contribute some code to the project Smiley

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Google dot what?
*
Posts: 2
12 credits
Members referred : 0


« Reply #7 on: Dec 07, 2007, 04:56:00 pm »

Nikolas - I found the issue.  I was testing this on a subdomain, and I had set the cookie domain to be sub.domain.com.  When I reset the cookie domain to be www.sub.domain.com everything worked fine as it should.  Thx for your code again, it's working great!
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=7301
Tags : php user class class open source Bookmark this thread : Digg Del.icio.us Dzone more....

Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  PhP  >  Php User Class
Topic: Version 0.9 released
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 28, 2012, 08:59:16 pm





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!






Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2012 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.