Simple Invoices logo
    • CommentAuthorGrayson
    • CommentTimeJul 14th 2007 edited
     permalink
    I installed today and have been testing.

    I notice the "Log in" button on the menu and have played around with it.

    I tend to be "logged in" no matter what I do. That opens up a major security faulkt for my purposes. Can someone explain this, please?

    My si_users table did not install from the downloaded original sql statement. I copied the one mentioned on another thread ... but still no differences seen! :?

    All other features are great and exactly what I've been seeking. :lol:



    Thanks
    • CommentAuthorantx
    • CommentTimeJul 15th 2007 edited
     permalink
    • CommentAuthorGrayson
    • CommentTimeJul 15th 2007 edited
     permalink
    Yes, I have done that but now can't log in at all. How does one create a new user and password?

    The three in the sql state do not work for me.

    Thanks
    • CommentAuthorGrayson
    • CommentTimeJul 15th 2007 edited
     permalink
    have also created a user/pass in phpmyadmin with no luck. :'(
    • CommentAuthorjustin
    • CommentTimeJul 15th 2007 edited
     permalink
    hey

    re user/pass

    if you have already modified your include_auth.php file, then its either an issue with your sql or config.php

    for further debugging please post your config.php and the backup of your si_users table

    Cheers

    Justin
    • CommentAuthorGrayson
    • CommentTimeJul 16th 2007 edited
     permalink
    I turned ChallengeLife to off and it seems to work now.
    • CommentAuthorjustin
    • CommentTimeJul 16th 2007 edited
     permalink
    good to hear

    theres still some issues with the ChallengeLife and MD5 stuff - but should work fine if on defaults

    Cheers

    Justin
    • CommentAuthorDangerBoy
    • CommentTimeJul 31st 2007 edited
     permalink

    good to hear

    theres still some issues with the ChallengeLife and MD5 stuff - but should work fine if on defaults

    Cheers

    Justin



    I still have problems with this issue :'( , I changed the MD5 to be on and switched the changelife off, but this however logs you in with anything typed in at login, I had to adjust the changelife back to 480 because of the security issue posed, so I cant login now :|

    Please assist, I have changed evertything as shown in the forum topic posted that solved this...
    • CommentAuthorDangerBoy
    • CommentTimeAug 1st 2007 edited
     permalink
    I managed to solve this problem by placing password policies on the directory on my webserver, however this effects the pdf export :(
    Ciao for now :D
    BTW I moved to a php 5 server with XSLT supported and it worked like a charm.
    • CommentAuthoraplysia
    • CommentTimeAug 2nd 2007 edited
     permalink
    The problem with pdf-export and .htaccess is solved in the next version...