Re: Re: cvs: pearweb /public_html login.php
| From: | Jim Winstead | Date: | Tue, 26 Nov 2002 03:58:18 +0000 |
| Subject: | Re: Re: cvs: pearweb /public_html login.php | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-11096@lists.php.net to get a copy of this message | ||
but someone doing development on the site may want to run a local copy
so that they can test their changes before checking them in and
inflicting them on everyone else. always a friendly thing to do. :)
jim
On Sun, Nov 24, 2002 at 06:38:00PM -0000, Jon Wood wrote:
> Does anyone but the PEAR server admins need to be able to run the PEAR site
> anyway?
>
> Isn't the idea that it's a central place to keep the repository, which would
> be missed if people ran their own pearwebs...
>
> Jon
>
> -----Original Message-----
> From: Jim Winstead [mailto:jimw@apache.org]
> Sent: 24 November 2002 17:41
> To: Richard Heyes
> Cc: PEAR Dev
> Subject: [PEAR-DEV] Re: [PEAR-CVS] Re: cvs: pearweb /public_html
> login.php
>
>
> On Sun, Nov 24, 2002 at 12:07:45PM -0000, Richard Heyes wrote:
> > > > Been thinking about this. It would be even more secure if we could
> hash
> > with
> > > > two secrets, ie the password and some other secret. Problem is, with
> > pearweb
> > > > being open to the public this isn't really feasible, unless we use an
> > > > encoded function to do the hashing. I can supply the encoded function,
> > if we
> > > > can get the Optimizer installed on pearweb.
> > > >
> > > > How does this sound ?
> > >
> > > it would be much simpler to read a file stored outside of the web tree
> > > to get the server's secret, and that's less likely to break when someone
> > > upgrades php on that machine.
> >
> > Kinda screws up portability though, since if it's not in cvs, it will have
> > to be retrieved separately by devs.
>
> devs shouldn't need the server secret. it wouldn't be a secret then. :)
>
> (and requiring the optimizer is likely to be more inconvenient for devs,
> who are more likely to be running between-releases versions of php.)
>
> jim
>
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>