unsecure admin-area
Reported by Johannes Schirge | 2009-05-18 15:44:26 UTC | in 0.6
Hey, first I thought it't a bug of the dev-version, but I am able to access to /admin as a non-admin or non-registered user. Should be fixed soon :)
Comments and changes to this ticket
-

Brian Jesse Hendrickson 2009-05-18 15:52:57 UTC
- State changed from new to open
yes can see the admin area but not make changes
omb has a very good (though still new and buggy) centralized security model
but yes, agreed, should not be able to see it at all
-

Johannes Schirge 2009-05-18 22:25:22 UTC
Hmm...I just edited your first categorie on openmicroblogger.com/admin
-

-

Brian Jesse Hendrickson 2009-05-18 22:42:54 UTC
insert these 4 lines at line 1508 of /db/library/dbscript/_functions.php
if ( !( in_array( $request->action, $datamodel->allowed_methods, true )))
$action = 'get';if (!($action == 'get'))
return false; -

Brian Jesse Hendrickson 2009-05-18 22:43:44 UTC
the public_resource() test is supposed to return true only for GET on a resource
-

Brian Jesse Hendrickson 2009-05-18 22:44:25 UTC
if you want to push the fix I will pull it from your git
-

Brian Jesse Hendrickson 2009-05-18 22:48:48 UTC
should have an $action = $request->action; before that too
$action = $request->action;
if ( !( in_array( $action, $datamodel->allowed_methods, true )))
$action = 'get';if (!($action == 'get'))
return false; -

-

Brian Jesse Hendrickson 2009-05-18 22:56:24 UTC
glad you like it! :-)
I can push it if you don't want to
-

Johannes Schirge 2009-05-18 22:59:47 UTC
Oh, you can't visit the mainpage anymore without being logged in.
If you fix that, you can push it :P
-

Brian Jesse Hendrickson 2009-05-18 23:03:33 UTC
fixed like this
I will push
$action = $request->action;
if ( !( in_array( $action, $datamodel->allowed_methods, true )))
$action = 'get';if (!($action == 'get' || $action == 'get'))
return false; -

-

Brian Jesse Hendrickson 2009-05-18 23:05:16 UTC
are you sure? did you use the 5-line version? I can see home page not logged in
-

Brian Jesse Hendrickson 2009-05-18 23:05:42 UTC
$action = $request->action;
if ( !( in_array( $action, $datamodel->allowed_methods, true )))
$action = 'get';
if (!($action == 'get'))
return false;
-

Johannes Schirge 2009-05-18 23:44:54 UTC
Okay, didn't get the 5 line version. now it works with your last post. Thanks! :)
-

Brian Jesse Hendrickson 2009-05-19 00:05:13 UTC
hi Johannes,
I just committed all of your fixes, and the security fix too
http://github.com/voitto/openmicroblogger/commits/master
also posted a new dbscript.net/omb.zip
thanks again for your help -brian
-

Brian Jesse Hendrickson 2009-05-19 00:05:23 UTC
- State changed from open to resolved
-

Scot 2009-05-20 08:12:19 UTC
Playing around in Identi.ca I noticed an old test account that is still listed by another Identi.ca user under "subscribers.
While the link showed an old Sportstwit profile url (http://www.sportstwit.com/admin), it actually brought me to: http://openmicroblogger.com/admin.
This can't be good,
-

Brian Jesse Hendrickson 2009-05-22 00:24:29 UTC
- State changed from resolved to open
-

Brian Jesse Hendrickson 2009-06-17 17:40:29 UTC
Hi Scot,
Could you do me a favor and look at the contents of the .htaccess file at SportsTwit.com
My guess is that the 3rd line says "openmicroblogger.com"
Thanks a lot
-- Brian
-

Johannes Schirge 2009-06-28 06:24:59 UTC
- Tag changed from admin-area, security-issue to medium-priority
Is this still a problem?
-

Johannes Schirge 2009-07-20 05:56:54 UTC
- State changed from open to resolved
Okay, no one instead of the admin is able to access the admin menu anymore. Good thing :-)
Please Sign in or create a free account to add a new ticket.
With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.
Create your profile
Help contribute to this project by taking a few moments to create your personal profile. Create your profile ยป
a(nother) PHP implementation of the http://openmicroblogging.org standard for distributed microblogging. Compatible with identi.ca and laconi.ca