|
Korru
Shitlord
| Reputation: 33 | Group: | Elite | Posts: | 4,267 | Joined: | Jun 26, 2012 |
| Post #391: 18th Feb 2015 6:46 PM | |
Thx Paul | |
| | |
Mercator
The Last Snowcrab
| Reputation: 133 | Group: | Overlord | Posts: | 11,515 | Joined: | Jun 26, 2012 |
| Post #392: 18th Feb 2015 7:01 PM | |
Porl can you fix how the likes and reputation works, sending the user cookies or whatever and validate who it is serverside instead of sending the ID of the user in the post data and assume it's his.
I could have seen the names of everyone on Korr's scum board by making them like a post so it's a problem. | |
http://i.imgur.com/1upHc7K.png |
|
| | |
PORL
UNFORGIVABLE
| Reputation: 153 | Group: | Admin | Posts: | 4,222 | Joined: | Jun 22, 2012 |
| Post #393: 18th Feb 2015 7:05 PM | |
|
Porl can you fix how the likes and reputation works, sending the user cookies or whatever and validate who it is serverside instead of sending the ID of the user in the post data and assume it's his.
I could have seen the names of everyone on Korr's scum board by making them like a post so it's a problem. |
I agree it's a problem and I'm glad you broke it because I'd honestly forgotten about it. The like and rep features were written very quickly. I had about half a day to work on them so I cut corners because nobody was really using the software at the time anyway.
I can put some server side validation in without too much trouble.
I'm working on some other stuff at the moment which is why I've not rushed it along, but for a game where players lists need to be secret I can see why it's important. | |
| | |
Korru
Shitlord
| Reputation: 33 | Group: | Elite | Posts: | 4,267 | Joined: | Jun 26, 2012 |
| Post #394: 18th Feb 2015 7:08 PM | |
|
Porl can you fix how the likes and reputation works, sending the user cookies or whatever and validate who it is serverside instead of sending the ID of the user in the post data and assume it's his.
I could have seen the names of everyone on Korr's scum board by making them like a post so it's a problem. |
/facedesk | |
| | |
Mercator
The Last Snowcrab
| Reputation: 133 | Group: | Overlord | Posts: | 11,515 | Joined: | Jun 26, 2012 |
| Post #395: 18th Feb 2015 7:09 PM | |
Yeah I didn't think it was really a problem until I figured that out. | |
http://i.imgur.com/1upHc7K.png |
|
| | |
PORL
UNFORGIVABLE
| Reputation: 153 | Group: | Admin | Posts: | 4,222 | Joined: | Jun 22, 2012 |
| Post #396: 18th Feb 2015 7:23 PM | |
Try breaking the like/dislike and rep system now. I've put some checks in place. It still sends all the data in the same way but it should look at the session data you have in your cookies and block all attempts at reps/likes that aren't yours. | |
| | |
Mercator
The Last Snowcrab
| Reputation: 133 | Group: | Overlord | Posts: | 11,515 | Joined: | Jun 26, 2012 |
| Post #397: 18th Feb 2015 7:31 PM | |
It works! | |
http://i.imgur.com/1upHc7K.png |
|
| | |
Mercator
The Last Snowcrab
| Reputation: 133 | Group: | Overlord | Posts: | 11,515 | Joined: | Jun 26, 2012 |
| Post #398: 18th Feb 2015 7:32 PM | |
RIP my rep powers. | |
http://i.imgur.com/1upHc7K.png |
|
| | |
Korru
Shitlord
| Reputation: 33 | Group: | Elite | Posts: | 4,267 | Joined: | Jun 26, 2012 |
| Post #399: 18th Feb 2015 7:36 PM | |
much better now, I was thinking putting a brighter transparent image on top when you hover over it, but this will do. Thx von Paul. | |
| | |
PORL
UNFORGIVABLE
| Reputation: 153 | Group: | Admin | Posts: | 4,222 | Joined: | Jun 22, 2012 |
| Post #400: 18th Feb 2015 7:40 PM | |
I had no objection to you being rep demi-god until you used it to praise vernon. At that point there had to be retribution. | |
| | |
Mercator
The Last Snowcrab
| Reputation: 133 | Group: | Overlord | Posts: | 11,515 | Joined: | Jun 26, 2012 |
| Post #401: 18th Feb 2015 7:51 PM | |
|
I had no objection to you being rep demi-god until you used it to praise vernon. At that point there had to be retribution. |
The lord must giveth to taketh. | |
http://i.imgur.com/1upHc7K.png |
|
| | |
Curtis
First Place Dick
| Reputation: 1,170 | Group: | Admin | Posts: | 79,236 | Joined: | Jun 22, 2012 |
| Post #402: 18th Feb 2015 10:24 PM | |
PAUL'S A BEAST | |
| | |
Korru
Shitlord
| Reputation: 33 | Group: | Elite | Posts: | 4,267 | Joined: | Jun 26, 2012 |
| Post #403: 24th Feb 2015 12:15 PM | |
Paul do you remember programming that javascript player roster thing for ATTWS? Is there a way when mouseovering a picture to get another image to show instead of a tooltip? Being a shitty script kiddie, I've tried to change variables around to get the background to show an image instead of a dull color background but failed miserably... | |
| | |
PORL
UNFORGIVABLE
| Reputation: 153 | Group: | Admin | Posts: | 4,222 | Joined: | Jun 22, 2012 |
| Post #404: 24th Feb 2015 4:18 PM | |
I dunno if you can without messing with the script file, which you can't do since it's hosted on the NDim Side. I'll have to play around with it to see. | |
| | |
Ben
Serial Killer
| Reputation: 115 | Group: | Legend | Posts: | 6,688 | Joined: | Oct 20, 2014 |
| Post #405: 25th Feb 2015 10:53 PM | |
I'm not sure how to attach a screen shot saved on my desktop as a pdf here, but I can email it if that helps, and I also have the same issue on my tablet. But when I am typing in the 'Add Reply' like right now, there are no BBC codes above to modify the text. Any suggestions on why?
They are there when I create a new thread for the 1st post and when I click to edit a post.
| |
| | |
1 Users Viewing (1 Guests) |
|
|