|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150 |
|
|
|
|
|
Joined: Dec 2003
Posts: 1,798 Likes: 2
Pooh-Bah
|
|
Pooh-Bah
Joined: Dec 2003
Posts: 1,798 Likes: 2 |
The site navigation. I have a client who attempts something similar, tho even I skip it and just enter the forums directly to skip the overhead.
Difficult to do, especially if trying to use frames.
|
|
|
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150 |
Still not really clear to me but I'll just say, frames are dirty.
|
|
|
|
|
Joined: Apr 2007
Posts: 3,940 Likes: 1
Former Developer
|
|
Former Developer
Joined: Apr 2007
Posts: 3,940 Likes: 1 |
you must feel icky every time you use phpMyAdmin then 
|
|
|
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150 |
I do, I do... But then I think to myself, it's not publicly viewable so i don't have to worry about search engines and "alternative browsers" checking out my content 
|
|
|
|
|
Joined: Jul 2007
Posts: 17
stranger
|
|
stranger
Joined: Jul 2007
Posts: 17 |
Hello Gizmo, The UBB-threads is a part of a website acting like a corporate intranet. Anonymous users can browse only a part of the site and they cannot view the forum. Only if you are autenticated on the site you can access the forum-link on the site navigation. So autenticated website users are non-authenticated viewers on the ubb-threads. So you need an extra login to post.
On the old server (running classic) this is done this way. If you go to the forum directly(lets say by bookmark), you will be presented with the websites log-in screen (the former programmer went away due to a quarel so i can't ask him how he did it)
I know this sounds complicated Gizmo, but due to sensitive content, this is the way want it. Ans so far it works for them....
Thanx btw: i guess i can password-protect the forum directory, but thats not the way i like to do it, since the site is running it's own authenication module.
|
|
|
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150 |
I'd just use .htpasswd authentication on the forum directory; then users can have their own "forum access" password, and forum account; or you could use a "forum password" using htpassd and just have it so that it's a genaric user/pass and only let employees know the password...
You could additionally require login on every forum, then turn on the registration queue and only approve those who should be approbed as well...
|
|
|
|
|
Joined: Jul 2007
Posts: 17
stranger
|
|
stranger
Joined: Jul 2007
Posts: 17 |
hmm, this means 3 passwords, 1 for the site, 1 for forumaccess, 1 for forummembership. To me it sounds like one too many.
Maybe the best thing then is to make all forums passwordprotected, so "viewers" also have to be forummembers.
I saw some discussions on this topic on this forum.
You agree?
|
|
|
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150 |
I do agree that using the forums permission system is the best bet; passwords are horrible security to rely on, as they can be easily given out; utilizing the grouping system in the UBB to add members makes it just that much easier to revoke them from those groups.
|
|
|
|
|
Joined: Jul 2007
Posts: 17
stranger
|
|
stranger
Joined: Jul 2007
Posts: 17 |
Hello Gizmo, sorry to bother you again, but before i go on: I'm using drupal CMS and see now that for phpBB they have a module to integrate the forum into their CMS. It's not a "real" integration (it fiddles around with the .htaccess!) but it works!
I'm not prepared to switch to phpBB, so.. do you have anything similar??
|
|
|
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150 |
Before you even consider moving to phpbb I'd highly suggest you research its vast history of security issues...
As for CMS integrations, I can't say that I've seen any; the majority that I've seen are for chat services (i think theres a post about different integration options around here somewhere within the last 60 days).
|
|
|
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150
|
|
Joined: Jun 2006
Posts: 16,533 Likes: 150 |
I believe the thread I mentioned is clicky
|
|
|
|
|
Joined: Nov 2006
Posts: 3,097 Likes: 1
Carpal Tunnel
|
|
Carpal Tunnel
Joined: Nov 2006
Posts: 3,097 Likes: 1 |
(the former programmer went away due to a quarel so i can't ask him how he did it) Well then why not have the new programmer review the code or create something new? I would think a good programmer could whip something up within say a month. Better would be to integrate some other current authentication system. Not sure of your infrastructure but if Windows and AD then maybe something along these lines http://www.windowsnetworking.com/articles_tutorials/Authenticating-Linux-Active-Directory.html
|
|
|
|
1 members (Gizmo),
771
guests, and
133
robots. |
|
Key:
Admin,
Global Mod,
Mod
|
|
|
|