Page 1 of 1

Nice to see the forum back

Posted: Sun Dec 03, 2017 8:01 pm
by Lord
Looks like everything is ok. :D

Re: Nice to see the forum back

Posted: Sun Dec 03, 2017 8:14 pm
by SeregaZ
yes, but how to know what new items is in this new version?

Re: Nice to see the forum back

Posted: Sun Dec 03, 2017 8:45 pm
by mk-soft
As it looks like, the server has moved to England.

Re: Nice to see the forum back

Posted: Mon Dec 04, 2017 7:39 am
by Lord
Brexit exit? :wink:

Re: Nice to see the forum back

Posted: Mon Dec 04, 2017 9:44 am
by SeregaZ
it was russians hackers! :twisted:

Re: Nice to see the forum back

Posted: Mon Dec 04, 2017 10:10 pm
by Sicro
Since the forum is online again, the login needs the sid-parameter ("http://www.purebasic.fr/english/index.php?sid=e4e12..."). In the previous forum version, the sid-parameter was also appended to the URL, but the login didn't depend on this parameter because all the required data was stored in a cookie. As it is now, someone only needs a URL with the sid-parameter of the logged in user and he is also logged in as the user without having the cookie. I find that dangerous. In the past I have seen some forum members posting URLs to forum threads or forum posts that still contained the sid-parameter.

Unfortunately, the forum still does not use an encrypted connection ("https://"). Our login data (user name and password) are sent through the Internet in plain text.
For the website of PureBasic was changed to "https://" ([Done] https://www.purebasic.com), why not also for the forum (Forum login isn't protected (https))?

Edit:
The text, which I have now colored green above, seems to work only with Firefox and only locally on the computer, as I have now noticed.
In a few days I have enough time again to investigate the problem further. I will then edit this post again.

Edit 2:
It looks like someone from the PB team has changed the forum configuration, because now only the logout link contains the sid parameter.