rejetto forum
May 25, 2012, 08:48:17 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: This forum is free, you do NOT need to register to post. But you may.
PROBLEMS? QUESTIONS? CLICK HERE!
Fill the survey!
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: experiment  (Read 1979 times)
0 Members and 1 Guest are viewing this topic.
rejetto
Administrator
Insane programmer
*
Offline Offline

Italy Italy

Posts: 11831


View Profile
« on: October 18, 2010, 05:20:25 AM »

i'm experimenting with session based login.
there's logout too.
in this build a default template supporting it is included.
it should be compatible with old login, and thus old templates.
if javascript is enabled the login is also secure without SSL.
comments are welcome.

www.rejetto.com/hfs.exe
Logged
bacter
Operator
Insane poster
*****
Offline Offline

Spain Spain

Posts: 679


View Profile
« Reply #1 on: October 18, 2010, 11:04:28 AM »

Login and logout works with new template in FF and chrome, with old templates login works too. But there seems no way to add a section logout [logout] to old templates without ajax - but this is ok, so we have to move to ajax what opens new ways to add features to our templates.
Logged

your computer has no brain - use your own !
maverick
Insane poster
*****
Offline Offline

Posts: 1056


Computer Solutions


View Profile
« Reply #2 on: October 18, 2010, 11:36:55 AM »

Login and logout also works with new default template in Opera.

I wouldn't mind adding a logout function to my customized template, but have no idea what is needed to add ajax to it.
Logged

maverick
r][m
Insane poster
*****
Offline Offline

United States United States

Posts: 340


View Profile
« Reply #3 on: October 18, 2010, 12:49:39 PM »

I wouldn't mind adding a logout function to my customized template, but have no idea what is needed to add ajax to it.

I would also like to do this, but have little time to learn ajax.
Actually, I fear extensive use of ajax will cause an end to hfs for me.

@ Rejetto
With Firefox on Ubuntu/Wine logout didn't work.
Does this version or tpl have to be connected to the internet to function?
I noticed it tries to connect to google apis on my test machine, on XP Pro, which is LAN only.
Since it couldn't connect, it wouldn't load.
« Last Edit: October 18, 2010, 02:32:22 PM by r][m » Logged
rejetto
Administrator
Insane programmer
*
Offline Offline

Italy Italy

Posts: 11831


View Profile
« Reply #4 on: October 19, 2010, 05:51:51 AM »

new login doesn't require ajax.
for non-ajax usage just remove the __AJAX parameter.
indeed i said it works without javascript. There's no ajax without javascript. Wink
anyway atm i decently tested only javascript/ajax version, but the default template is (meant to be) designed to gracefully degrade without javascript.

don't get me wrong. I mean ajax is to get a better experience. Old features are planned to stay as they are without it.
maybe i will provide a standard template without javascript at all just as a bare bone for the faints of heart.
Is this guideline ok for you?
« Last Edit: October 19, 2010, 05:56:40 AM by rejetto » Logged
MJC
Occasional poster
*
Offline Offline

United States United States

Posts: 1


View Profile
« Reply #5 on: October 19, 2010, 12:14:38 PM »

i'm experimenting with session based login.
there's logout too.
in this build a default template supporting it is included.
it should be compatible with old login, and thus old templates.
if javascript is enabled the login is also secure without SSL.
comments are welcome.

www.rejetto.com/hfs.exe


Wow, what a great version!  Nice job!  Any chance this will end up in the new high-speed hfs version?  I just got Verizon FIOS (35/35 pipe) installed and the old high-speed version allowed me to move a 110MB file in just a few seconds!  Would love to see this new version as high-speed!  Keep up the great work Rejetto!
Logged
rejetto forum
« Reply #5 on: October 19, 2010, 12:14:38 PM »

Do you like this software? Consider even $2
 Logged
etherknight
Regular poster
**
Offline Offline

United States United States

Posts: 23


View Profile Email
« Reply #6 on: October 21, 2010, 04:23:12 PM »

Quote
if javascript is enabled the login is also secure without SSL.

I think the term 'secure' should be taken with fairly large grain of salt. If the mechanics would be as I think they would be (e.g. using JS to leverage an MD5 and relying on either cookies or IP stability), then it would ever-so-slightly more secure than plain text across the WAN. Maybe it's being done an entirely different way, I don't know. But there are only so many ways JS could do this....

Not an issue for those who don't serve anything terribly sensitive. But we all know there are others who serve up for unsavory or less-than-legal material. I would caution those ones against thinking of a non-SSL login as 'secure'.
Logged
rejetto
Administrator
Insane programmer
*
Offline Offline

Italy Italy

Posts: 11831


View Profile
« Reply #7 on: November 01, 2010, 08:19:41 AM »

you are right, but getting never 100% security with our computers, you should state HOW secure it is, and there's no standard i know to measure such security.
so having no good way, i just say "it's okay" (secure) and "not okay". Highly debatable, but it's good for non-techies (and it's short!).
Techies will be good to value this security on their own, and relating it to their needs. Wink


Just at a glance, i would say a man-in-the-middle attack should be hard enough with such configuration. Any opinion on this is welcome.
« Last Edit: November 01, 2010, 08:23:26 AM by rejetto » Logged
johnjaykay
Regular poster
**
Offline Offline

United States United States

Posts: 21


View Profile Email
« Reply #8 on: November 19, 2010, 02:18:03 PM »

you are right, but getting never 100% security with our computers, you should state HOW secure it is, and there's no standard i know to measure such security.
so having no good way, i just say "it's okay" (secure) and "not okay". Highly debatable, but it's good for non-techies (and it's short!).
Techies will be good to value this security on their own, and relating it to their needs. Wink


Just at a glance, i would say a man-in-the-middle attack should be hard enough with such configuration. Any opinion on this is welcome.

I think this software is the best you're gonna find for the money (FREE). If there's a feature you don't like or a problem with it, why not spend money and have someone fix it, or donate to them and help find an answer to the solution.


@rejetto...software is great! Helps me access my files every day.  I appreciate the hard work and effor on this.

John
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!


Google visited last this page May 24, 2012, 02:44:25 PM