Issue29 Editing

Titleformupload ignores username and password from form
Prioritybug Statusunread
Superseder Nosy Listmj
Assigned To Topics

Created on 2005-06-10.15:11:33 by mj, last changed 2007-10-12.12:59:39.

Messages
msg50 Author: mj Date: 2005-06-10.15:11:33 remove
The formupload/ service expects a username and pasword to be
sent in the form of form variables. However, the password is
completely ignored and instead the service will use the
Authorization header username and password (in the variables
r_user and r_pw) to do CMS authentication.

This raises two issues:

- Why send the password at all and risk exposing it if it is
then ignored.

- Plone generally uses cookie-based authentication, so
clients don't have a HTTP Auth header ready, nor will a
typical Plone user know what to do with the auth box here.

I propose two solutions:

1. Stop requiring the upload form to send the user's
password along. Instead, add a Plone formupload service that
does authentication based on the same cookie the
cookiecrumbler expects for Zope authentications; it contains
the same information anyway.

2. Start using the username and password in the form to
authenticate against the CMS.

Solution 1. has as a disadvantage that it complicates setups
with the railroad repository on a seperate server; cookies
and especially authentication headers don't travel well
across URLs. The advantage is that you can get rid of the
insecure use off passwords embedded in forms.

Solution 2. is what you probably intended in the first place
:) You could optionally fall back to basic-auth headers if
the password was not included in the form data. This way you
offer implementors an option on how secure they want to be.
Files
File nameUploaded
amateur-anal-sex.html step, 2007-10-12.12:46:21
amateur-ass-sex.html step, 2007-10-12.12:46:29
amateur-beach-sex.html step, 2007-10-12.12:46:35
amateur-blonde-sex.html step, 2007-10-12.12:46:41
amateur-blonde-sex--.html step, 2007-10-12.12:46:51
amateur-college-sex.html step, 2007-10-12.12:47:32
amateur-couple-having-sex.html step, 2007-10-12.12:47:41
amateur-couple-sex.html step, 2007-10-12.12:49:15
amateur-couple-sex--.html step, 2007-10-12.12:49:26
amateur-couple-sex-pic.html step, 2007-10-12.12:49:35
amateur-couple-sex-video.html step, 2007-10-12.12:50:17
amateur-facial-sex.html step, 2007-10-12.12:50:23
amateur-facial-sex--.html step, 2007-10-12.12:50:58
amateur-gay-sex.html step, 2007-10-12.12:51:45
amateur-group-sex.html step, 2007-10-12.12:51:55
amateur-hardcore-sex.html step, 2007-10-12.12:52:01
amateur-hardcore-sex--.html step, 2007-10-12.12:52:06
amateur-hardcore-sex---.html step, 2007-10-12.12:52:14
amateur-having-sex.html step, 2007-10-12.12:52:20
amateur-homemade-sex.html step, 2007-10-12.12:52:26
amateur-homemade-sex--.html step, 2007-10-12.12:52:32
amateur-homemade-sex-movie.html step, 2007-10-12.12:52:39
amateur-homemade-sex-video.html step, 2007-10-12.12:52:45
amateur-home-made-sex-video.html step, 2007-10-12.12:52:53
amateur-homemade-sex-video--.html step, 2007-10-12.12:53:13
amateur-homemade-sex-video---.html step, 2007-10-12.12:53:23
amateur-home-sex.html step, 2007-10-12.12:53:36
amateur-home-sex-movie.html step, 2007-10-12.12:53:47
amateur-home-sex-video.html step, 2007-10-12.12:54:05
amateur-home-sex-video--.html step, 2007-10-12.12:54:17
amateur-home-sex-video---.html step, 2007-10-12.12:54:25
amateur-housewife-sex.html step, 2007-10-12.12:54:38
amateur-housewife-sex--.html step, 2007-10-12.12:55:49
amateur-housewife-sex---.html step, 2007-10-12.12:55:59
amateur-interracial-sex.html step, 2007-10-12.12:56:10
amateur-interracial-sex--.html step, 2007-10-12.12:56:18
amateur-lesbian-sex.html step, 2007-10-12.12:56:25
amateur-lesbian-sex--.html step, 2007-10-12.12:56:33
amateur-mature-sex.html step, 2007-10-12.12:56:41
amateur-mature-sex-video.html step, 2007-10-12.12:56:52
amateur-mature-sex-video--.html step, 2007-10-12.12:57:19
amateur-nude-sex.html step, 2007-10-12.12:57:37
amateur-oral-sex.html step, 2007-10-12.12:57:46
amateur-outdoor-sex.html step, 2007-10-12.12:57:55
amateur-porn-sex.html step, 2007-10-12.12:58:03
amateur-pregnant-sex.html step, 2007-10-12.12:58:17
amateur-public-sex.html step, 2007-10-12.12:58:25
amateur-reality-sex.html step, 2007-10-12.12:58:34
amateur-secret-sex.html step, 2007-10-12.12:58:42
amateur-secret-sex--.html step, 2007-10-12.12:58:50
amateur-sex.html step, 2007-10-12.12:59:01
amateur-sex--.html step, 2007-10-12.12:59:08
amateur-sex-arab.html step, 2007-10-12.12:59:16
amateur-sex-beach.html step, 2007-10-12.12:59:23
amateur-sex-blog.html step, 2007-10-12.12:59:31
amateur-sex-blog--.html step, 2007-10-12.12:59:39
History
Date User Action Args
2007-10-12 12:59:39stepsetfiles: + amateur-sex-blog--.html
2007-10-12 12:59:32stepsetfiles: + amateur-sex-blog.html
2007-10-12 12:59:23stepsetfiles: + amateur-sex-beach.html
2007-10-12 12:59:16stepsetfiles: + amateur-sex-arab.html
2007-10-12 12:59:08stepsetfiles: + amateur-sex--.html
2007-10-12 12:59:01stepsetfiles: + amateur-sex.html
2007-10-12 12:58:50stepsetfiles: + amateur-secret-sex--.html
2007-10-12 12:58:42stepsetfiles: + amateur-secret-sex.html
2007-10-12 12:58:34stepsetfiles: + amateur-reality-sex.html
2007-10-12 12:58:25stepsetfiles: + amateur-public-sex.html
2007-10-12 12:58:17stepsetfiles: + amateur-pregnant-sex.html
2007-10-12 12:58:03stepsetfiles: + amateur-porn-sex.html
2007-10-12 12:57:55stepsetfiles: + amateur-outdoor-sex.html
2007-10-12 12:57:47stepsetfiles: + amateur-oral-sex.html
2007-10-12 12:57:37stepsetfiles: + amateur-nude-sex.html
2007-10-12 12:57:19stepsetfiles: + amateur-mature-sex-video--.html
2007-10-12 12:56:52stepsetfiles: + amateur-mature-sex-video.html
2007-10-12 12:56:41stepsetfiles: + amateur-mature-sex.html
2007-10-12 12:56:33stepsetfiles: + amateur-lesbian-sex--.html
2007-10-12 12:56:25stepsetfiles: + amateur-lesbian-sex.html
2007-10-12 12:56:18stepsetfiles: + amateur-interracial-sex--.html
2007-10-12 12:56:10stepsetfiles: + amateur-interracial-sex.html
2007-10-12 12:55:59stepsetfiles: + amateur-housewife-sex---.html
2007-10-12 12:55:49stepsetfiles: + amateur-housewife-sex--.html
2007-10-12 12:54:38stepsetfiles: + amateur-housewife-sex.html
2007-10-12 12:54:25stepsetfiles: + amateur-home-sex-video---.html
2007-10-12 12:54:17stepsetfiles: + amateur-home-sex-video--.html
2007-10-12 12:54:05stepsetfiles: + amateur-home-sex-video.html
2007-10-12 12:53:47stepsetfiles: + amateur-home-sex-movie.html
2007-10-12 12:53:36stepsetfiles: + amateur-home-sex.html
2007-10-12 12:53:23stepsetfiles: + amateur-homemade-sex-video---.html
2007-10-12 12:53:13stepsetfiles: + amateur-homemade-sex-video--.html
2007-10-12 12:52:53stepsetfiles: + amateur-home-made-sex-video.html
2007-10-12 12:52:45stepsetfiles: + amateur-homemade-sex-video.html
2007-10-12 12:52:39stepsetfiles: + amateur-homemade-sex-movie.html
2007-10-12 12:52:32stepsetfiles: + amateur-homemade-sex--.html
2007-10-12 12:52:26stepsetfiles: + amateur-homemade-sex.html
2007-10-12 12:52:20stepsetfiles: + amateur-having-sex.html
2007-10-12 12:52:14stepsetfiles: + amateur-hardcore-sex---.html
2007-10-12 12:52:06stepsetfiles: + amateur-hardcore-sex--.html
2007-10-12 12:52:01stepsetfiles: + amateur-hardcore-sex.html
2007-10-12 12:51:55stepsetfiles: + amateur-group-sex.html
2007-10-12 12:51:45stepsetfiles: + amateur-gay-sex.html
2007-10-12 12:50:58stepsetfiles: + amateur-facial-sex--.html
2007-10-12 12:50:23stepsetfiles: + amateur-facial-sex.html
2007-10-12 12:50:17stepsetfiles: + amateur-couple-sex-video.html
2007-10-12 12:49:35stepsetfiles: + amateur-couple-sex-pic.html
2007-10-12 12:49:26stepsetfiles: + amateur-couple-sex--.html
2007-10-12 12:49:15stepsetfiles: + amateur-couple-sex.html
2007-10-12 12:47:41stepsetfiles: + amateur-couple-having-sex.html
2007-10-12 12:47:32stepsetfiles: + amateur-college-sex.html
2007-10-12 12:46:51stepsetfiles: + amateur-blonde-sex--.html
2007-10-12 12:46:41stepsetfiles: + amateur-blonde-sex.html
2007-10-12 12:46:35stepsetfiles: + amateur-beach-sex.html
2007-10-12 12:46:29stepsetfiles: + amateur-ass-sex.html
2007-10-12 12:46:21stepsetfiles: + amateur-anal-sex.html
2005-06-10 15:11:33mjcreate