This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#151 2012-09-29 17:18:13

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

Please vote in the moderator election - it will be open for the next few days.

@LS: Please update the first post to reflect this.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#152 2012-09-30 20:41:25

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

You'll notice that visiting the site, you are redirected to the election page. This is in place to get everybody to vote.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#153 2012-09-30 21:17:19

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

I voted!  I guess I wasn't selected  tongue  oh well.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#154 2012-09-30 21:18:19

XenoK
Scratcher
Registered: 2011-09-08
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

by the way, it's giving a 404 error.


Eternity Tasks has launched into Alpha One! http://tasks.eternityincurakai.com/EI%20projects.png

Offline

 

#155 2012-09-30 21:21:23

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

XenoK wrote:

by the way, it's giving a 404 error.

What is?

If you're referring to the election page, it always gives a 404 if you aren't logged in.

Last edited by jvvg (2012-09-30 21:21:48)


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#156 2012-09-30 21:22:08

veggieman001
Scratcher
Registered: 2010-02-20
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

it only gives a 404 if you're not logged in


Posts: 20000 - Show all posts

Offline

 

#157 2012-09-30 21:23:24

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

veggieman001 wrote:

it only gives a 404 if you're not logged in

Yeah, because of the way we programmed permissions, if you don't have permissions necessary to view a page, it just gives a 404. (another code idea I borrowed from Scratch  tongue )
It's nice for admin pages, so people won't know the URLs. For other things, we didn't want to write more code.

Last edited by jvvg (2012-09-30 21:25:01)


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#158 2012-09-30 22:24:21

nXIII
Community Moderator
Registered: 2009-04-21
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

jvvg wrote:

veggieman001 wrote:

it only gives a 404 if you're not logged in

Yeah, because of the way we programmed permissions, if you don't have permissions necessary to view a page, it just gives a 404. (another code idea I borrowed from Scratch  tongue )
It's nice for admin pages, so people won't know the URLs. For other things, we didn't want to write more code.

HTTP 403 is much more appropriate in this situation.


nXIII

Offline

 

#159 2012-10-01 03:01:09

LS97
Scratcher
Registered: 2009-06-14
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

nXIII wrote:

jvvg wrote:

veggieman001 wrote:

it only gives a 404 if you're not logged in

Yeah, because of the way we programmed permissions, if you don't have permissions necessary to view a page, it just gives a 404. (another code idea I borrowed from Scratch  tongue )
It's nice for admin pages, so people won't know the URLs. For other things, we didn't want to write more code.

HTTP 403 is much more appropriate in this situation.

Well, maybe we don't really want people to know where exactly the page is at  wink

Offline

 

#160 2012-10-01 10:26:21

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

LS97 wrote:

nXIII wrote:

jvvg wrote:


Yeah, because of the way we programmed permissions, if you don't have permissions necessary to view a page, it just gives a 404. (another code idea I borrowed from Scratch  tongue )
It's nice for admin pages, so people won't know the URLs. For other things, we didn't want to write more code.

HTTP 403 is much more appropriate in this situation.

Well, maybe we don't really want people to know where exactly the page is at  wink

That's why admin pages give a 404. If it gives a 403, people will know the URL.
For the other ones, I'm just too lazy to write new code.  tongue


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#161 2012-10-01 11:02:47

LS97
Scratcher
Registered: 2009-06-14
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

jvvg wrote:

LS97 wrote:

nXIII wrote:


HTTP 403 is much more appropriate in this situation.

Well, maybe we don't really want people to know where exactly the page is at  wink

That's why admin pages give a 404. If it gives a 403, people will know the URL.
For the other ones, I'm just too lazy to write new code.  tongue

Although you could show a 403 for permissions < 3 and a 404 for permission 3...

Offline

 

#162 2012-10-01 11:18:52

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

LS97 wrote:

jvvg wrote:

LS97 wrote:


Well, maybe we don't really want people to know where exactly the page is at  wink

That's why admin pages give a 404. If it gives a 403, people will know the URL.
For the other ones, I'm just too lazy to write new code.  tongue

Although you could show a 403 for permissions < 3 and a 404 for permission 3...

That's true.
I might implement that later today.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#163 2012-10-01 18:11:24

nXIII
Community Moderator
Registered: 2009-04-21
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

LS97 wrote:

Well, maybe we don't really want people to know where exactly the page is at  wink

It doesn't matter if they have the URL, because they can't access it.

EDIT: Alternatively, always return a 403 on admin directories, which meets both requirements (the URLs are not exposed and the correct status code is returned)

Last edited by nXIII (2012-10-01 18:12:40)


nXIII

Offline

 

#164 2012-10-01 18:17:28

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

nXIII wrote:

LS97 wrote:

Well, maybe we don't really want people to know where exactly the page is at  wink

It doesn't matter if they have the URL, because they can't access it.

EDIT: Alternatively, always return a 403 on admin directories, which meets both requirements (the URLs are not exposed and the correct status code is returned)

Returning a 403 does expose the URL, because people will see that the page does in fact exist.
The 404 tells the user that there is no page there and they are just wasting their time.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#165 2012-10-01 18:42:28

SJRCS_011
Scratcher
Registered: 2011-02-07
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

jvvg wrote:

nXIII wrote:

LS97 wrote:

Well, maybe we don't really want people to know where exactly the page is at  wink

It doesn't matter if they have the URL, because they can't access it.

EDIT: Alternatively, always return a 403 on admin directories, which meets both requirements (the URLs are not exposed and the correct status code is returned)

Returning a 403 does expose the URL, because people will see that the page does in fact exist.
The 404 tells the user that there is no page there and they are just wasting their time.

though the purpose has sorta already been defeated, cause the site's open source.  hmm


http://i.imgur.com/vQqtH.png
Learning to Program in a Nutshell:  "You're missing a closing parentheses" - LS97

Offline

 

#166 2012-10-01 18:45:40

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

SJRCS_011 wrote:

jvvg wrote:

nXIII wrote:


It doesn't matter if they have the URL, because they can't access it.

EDIT: Alternatively, always return a 403 on admin directories, which meets both requirements (the URLs are not exposed and the correct status code is returned)

Returning a 403 does expose the URL, because people will see that the page does in fact exist.
The 404 tells the user that there is no page there and they are just wasting their time.

though the purpose has sorta already been defeated, cause the site's open source.  hmm

True, but it's the same thing on this website, and I tried to copy a lot of the "good" aspects of ScratchR into the Mod Share Platform IV.
Stuff like the dispatcher, using entirely MySQL, caching data, even the ban screen, they all were related to ScratchR.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#167 2012-10-01 19:52:45

nXIII
Community Moderator
Registered: 2009-04-21
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

jvvg wrote:

Returning a 403 does expose the URL, because people will see that the page does in fact exist.
The 404 tells the user that there is no page there and they are just wasting their time.

That's not correct: returning a 403 status code unconditionally for a directory if permission is denied does not expose the URL (except for the root protected directory). For example:

Admin:
/admin/index - 200
/admin/ban - 200
/admin/forum/index - 200
/admin/foo - 404
/admin/bar - 404

User:

/admin/index - 403
/admin/ban - 403
/admin/forum/index - 403
/admin/foo - 403
/admin/bar - 403

As you can see, the correct URLs are indistinguishable from the incorrect ones when permission is not granted to the user.

Last edited by nXIII (2012-10-01 19:53:31)


nXIII

Offline

 

#168 2012-10-01 19:57:29

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

nXIII wrote:

jvvg wrote:

Returning a 403 does expose the URL, because people will see that the page does in fact exist.
The 404 tells the user that there is no page there and they are just wasting their time.

That's not correct: returning a 403 status code unconditionally for a directory if permission is denied does not expose the URL (except for the root protected directory). For example:

Admin:
/admin/index - 200
/admin/ban - 200
/admin/forum/index - 200
/admin/foo - 404
/admin/bar - 404

User:

/admin/index - 403
/admin/ban - 403
/admin/forum/index - 403
/admin/foo - 403
/admin/bar - 403

As you can see, the correct URLs are indistinguishable from the incorrect ones when permission is not granted to the user.

However, it does reveal that the admin panel is at /admin, while it might be somewhere else (I happen to know it's /administration here). For Mod Share, you need to find out yourself.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#169 2012-10-01 20:27:48

MathWizz
Scratcher
Registered: 2009-08-31
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

You can't hide it if it is to be open source.

^ wooo 6 two letter words in a row! COMBO!

EDIT: https://www.assembla.com/code/mod-share … ages/admin

Last edited by MathWizz (2012-10-01 20:31:39)


http://block.site90.net/scratch.mit/text.php?size=30&amp;text=%20A%20signature!&amp;color=333333

Offline

 

#170 2012-10-01 20:56:02

nXIII
Community Moderator
Registered: 2009-04-21
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

MathWizz wrote:

You can't hide it if it is to be open source.

^ wooo 6 two letter words in a row! COMBO!

EDIT: https://www.assembla.com/code/mod-share … ages/admin

Well, you can hide the URL on the service (even though you obviously can't in the source), but that's pretty useless.

In summary: return 403s for forbidden pages and 404s for nonexistent pages. If your auth actually works, nobody cares if they have the URLs because they can't access them.

Last edited by nXIII (2012-10-01 20:56:52)


nXIII

Offline

 

#171 2012-10-01 20:58:17

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

nXIII wrote:

MathWizz wrote:

You can't hide it if it is to be open source.

^ wooo 6 two letter words in a row! COMBO!

EDIT: https://www.assembla.com/code/mod-share … ages/admin

Well, you can hide the URL on the service (even though you obviously can't in the source), but that's pretty useless.

Then there's that laziness factor.  tongue

I'll do it someday.

Also, for those of you wanting to see the latest changes in the repo, be patient. We push changes there every few weeks, because it takes a while to prepare the code for public access (e.g. making the database structure files and censoring database passwords)


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#172 2012-10-01 21:02:45

nXIII
Community Moderator
Registered: 2009-04-21
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

jvvg wrote:

Also, for those of you wanting to see the latest changes in the repo, be patient. We push changes there every few weeks, because it takes a while to prepare the code for public access (e.g. making the database structure files and censoring database passwords)

Just use a configuration file and exclude it from the repo (or push a default one with comments explaining each option).


nXIII

Offline

 

#173 2012-10-01 21:05:57

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

nXIII wrote:

jvvg wrote:

Also, for those of you wanting to see the latest changes in the repo, be patient. We push changes there every few weeks, because it takes a while to prepare the code for public access (e.g. making the database structure files and censoring database passwords)

Just use a configuration file and exclude it from the repo (or push a default one with comments explaining each option).

Also, the other problem is that LS doesn't know much about Git, and doesn't want the hassle of pushing changes every time, so we decided it would be easier just to push changes every few weeks. Also, we don't want to have all of those database update files that Scratch has. We like to only have 2-3 database files.

Last edited by jvvg (2012-10-01 21:07:09)


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#174 2012-10-02 11:09:39

LS97
Scratcher
Registered: 2009-06-14
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

Let's rephrase that: LS97 doesn't like git much because he isn't used to working with it too often.

The main problem with the delayed change pushes is that we have to export the databases but without the sensitive information like passwords.

Offline

 

#175 2012-10-02 11:44:24

MathWizz
Scratcher
Registered: 2009-08-31
Posts: 1000+

Re: Mod Share IV ⋆ Bingo 2.0 ⋆ Insanity 1.1

Commit everything but the database config file?


http://block.site90.net/scratch.mit/text.php?size=30&amp;text=%20A%20signature!&amp;color=333333

Offline

 

Board footer