Re: [rt.blitzed.org #189] staff site authentication
"David Leadbeater via RT" <[email protected]>
| Newsgroups | gmane.network.irc.blitzed.web |
|---|---|
| Message-ID | <[email protected]> |
<URL: http://rt.blitzed.org:80/Ticket/Display.html?id=189 > Andy Smith via RT wrote: > > <URL: http://rt.blitzed.org:80/Ticket/Display.html?id=189 > > > On Tue, Dec 16, 2003 at 06:53:52PM +0000, Philipp Kern via RT wrote: > > On Tue, 2003-12-16 at 19:43, Andy Smith via RT wrote: > > > I was also thinking of making this work over SSL now that we have > > > more IPs. This way, it could use your nick password instead of a > > > new staff password, which would be much nicer. Perhaps we could > > > look into a login page after I have made SSL work. > > > > Ok I guess best would be if you notify us over this ticket when SSL > > support is available (o: > > Yep. > > > (We shouldn't even implement a fallback to normal HTTP then if the > > normal nick password is used IMO) > > I am in two minds over having a HTTP version of staff.blitzed.org, > but dg says he has implemented a javascript/SHA1 way of sending > passwords securely so maybe that could be used. I think maybe what would be best is if http://blitzed.org/login/ was made to use SSL - then the staff site could use that along with the other things and things like quotes.blitzed.eu.org would benefit from SSL encrypted passwords.