From: Chad <ch...@ch...> - 2003-03-26 22:53:02
|
Well username and password should be system level for ftp functions, so=20= we wont need to have it in the config, just an accessable page by the=20 admin. Every change would require username and password. You could list calendars to be deleted by checklist buttons. Upload function could have a checkbox for 'overwrite' just for safety. If you went to the page when its not allowed by config, an error page=20 would occur much like RSS and Preferences. An individual page is fine and allows for more future expansion. Admin URL would be admin.php, but not linked anywhere on the page. README needs updated to explain this as well as config. I'll have more time next week to help with this, and get 0.9.2 out soon=20= after. -C On Wednesday, March 26, 2003, at 02:44 PM, Mike Traum wrote: > Hi, > I'm working on an interface=A0for calendar administration. Here's what = I=20 > have as a basic design: > Admin Options > - Update a calendar (replace a calendar file with a new one) > - Add a new calendar > - Delete a calendar > > New Pages > - Add 'admin.php' which will contain all of the functionality. When=20 > first accessing admin.php, it will prompt for username and password.=20= > After logging in, it will give the admin options detailed above. > > Configuration > - the admin page can be made to be inaccessible by a config.inc.php=20 > setting. This would be the default, I would guess. > - there will be only one user/password, which is configured in=20 > config.inc.php. afaik, this is a slight security problem, in that if=20= > something goes haywire with the server, it's possible that the text of=20= > config.inc.php could be obtained. That being said, it's the simpliest=20= > and I think sufficiently secure. > > Comments? > > mike > > > <image.tiff> > > Do you Yahoo!? > Yahoo! Platinum - Watch CBS' NCAA March Madness, live on your desktop!= |