Re: [vqwiki-dev] VQW-78 - do not store passwords in plain text
Status: Abandoned
Brought to you by:
mteodori
From: Martijn v. d. K. <mvd...@vq...> - 2006-04-22 19:16:52
|
Ryan, Just as an afterthought... :-) What happens when a user forgets the password? Just set the "first-use" property and the system generates another one? Gr Martijn Martijn van der Kleijn schreef: > Ryan, Andreas, > > I took a look at the code you sent and since it's switchable, go ahead > and put it in. > > About the testing.. I certainly believe yourself, Andreas and me try > to test everything. However, the more changes we make the more > possible new bug we introduce which we might miss.... however good we > test. Testing done using constantly modifying code is one thing, > testing using a frozen code system is another. It might turn up > nothing, it might turn up a single but critical release delaying bug. :-) > > Eventually, especially for 3.0, I want unit tests to cover most of the > code... that should cut down on our bugs and testing duration. > > Yours, Martijn > > ----- > Project Lead for the VQWiki Open Source project > > ----- Original Message ----- From: "Andreas Studer" <st...@gm...> > To: <ver...@li...> > Sent: Friday, April 21, 2006 10:33 PM > Subject: Re: [vqwiki-dev] VQW-78 - do not store passwords in plain text > > >> Hello Ryan >> >> If it is switchable, I set a vote to include this in vqwiki 2.7.8. >> >> Cheers >> >> Andreas >> >> >> Ryan Holliday wrote: >> >>>> and for this it is not explicitly required to do that. If we >>>> include this in the release 2.7.8 just keep in mind that we have to >>>> make a good Update-documentation about this and all other things >>>> (CSS and so on...). It will break existing properties. I normally >>>> keep the properties for reuse in a new vqwiki version. If the >>>> passwords will be encrypted, I must think about this in an >>>> upgrade... ;-) >>> >>> >>> >>> Hi Andreas - >>> >>> Actually it will not break existing properties. I've set the >>> "encode-properties" value to default false, so any existing >>> installation will work as before - I've tested copying old >>> properties files into a new version and it works. >>> >>> You're right that the documentation should be updated (I can do >>> that), and there is one new message string in ApplicationResources >>> that should be translated. >>> >>> If the team's preference is not to include a feature like this one >>> that's fine, I'm just trying to make my argument for what I feel is >>> a pretty important addition :) >>> >>> Ryan >>> >>> >>> ------------------------------------------------------- >>> Using Tomcat but need to do more? Need to support web services, >>> security? >>> Get stuff done quickly with pre-integrated technology to make your >>> job easier >>> Download IBM WebSphere Application Server v.1.0.1 based on Apache >>> Geronimo >>> http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 >>> >>> _______________________________________________ >>> veryquickwiki-develop mailing list >>> ver...@li... >>> https://lists.sourceforge.net/lists/listinfo/veryquickwiki-develop >>> >>> >> >> >> ------------------------------------------------------- >> Using Tomcat but need to do more? Need to support web services, >> security? >> Get stuff done quickly with pre-integrated technology to make your >> job easier >> Download IBM WebSphere Application Server v.1.0.1 based on Apache >> Geronimo >> http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 >> _______________________________________________ >> veryquickwiki-develop mailing list >> ver...@li... >> https://lists.sourceforge.net/lists/listinfo/veryquickwiki-develop >> > > > > ------------------------------------------------------- > Using Tomcat but need to do more? Need to support web services, security? > Get stuff done quickly with pre-integrated technology to make your job > easier > Download IBM WebSphere Application Server v.1.0.1 based on Apache > Geronimo > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 > _______________________________________________ > veryquickwiki-develop mailing list > ver...@li... > https://lists.sourceforge.net/lists/listinfo/veryquickwiki-develop > |