Re: mbox download username/password

From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Dave Page <dpage(at)pgadmin(dot)org>
Cc: PostgreSQL WWW <pgsql-www(at)postgresql(dot)org>
Subject: Re: mbox download username/password
Date: 2016-05-20 19:28:14
Message-ID: CABUevEzYi2Vk=XxRHTXaAgy-PxTJ363Ch5MtyL8gNb0fvugRLw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-www

On Fri, May 20, 2016 at 3:20 PM, Magnus Hagander <magnus(at)hagander(dot)net>
wrote:

> On Fri, May 20, 2016 at 10:30 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
>
>> Further to discussion at PGCon this morning, webkit based browsers no
>> longer display the realm text when displaying password prompts. This
>> was used by our archives code to tell the user what username/password
>> to enter when downloading mbox files (which are loosely protected
>> against bot downloads as they contain email addresses).
>>
>> The attached patch adds a note to the appropriate template to convey
>> the username/password info on the page. It's currently untested as I
>> don't have a pgarchives test environment.
>>
>> Magnus - can you test/apply please?
>>
>
> It's not just for mbox files though, it's also for viewing the raw
> messages. Don't we have the same problem there?
>
>
>
FWIW, this seems to be treated as a bug in Chrome:
https://bugs.chromium.org/p/chromium/issues/detail?id=544244 (comment 22
and forward, in particular the reference to the standard at #35)

So perhaps we should give it some time and see if they change?

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/

In response to

Responses

Browse pgsql-www by date

  From Date Subject
Next Message Dave Page 2016-05-20 20:48:29 Re: mbox download username/password
Previous Message Magnus Hagander 2016-05-20 19:20:46 Re: mbox download username/password