Xataface 1.3rc3 Released

News about Xataface

Xataface 1.3rc3 Released

Postby shannah » Wed Apr 13, 2011 11:45 am

I have released Xataface 1.3rc3 which includes improved to the site search feature, and adds some small security improvements.

Download it at:
http://sourceforge.net/projects/datafac ... z/download
or
http://sourceforge.net/projects/datafac ... p/download

Change log:

- Changed search results to show portions of page that match query
- Increased time limit on manage_build_index to unlimited - and closed session at
beginning of action to prevent user from being locked out.
- Fixed up the pluggable architecture for searches.
- Added IP address check in the session to prevent people from spoofing sessions
- Fixed search index to index entire record contents instead of just previews.
- Added optimize table command when building index.
- Improved site search options by making it so that you no longer need to have 2 types of
find_actions in order for the site search to work. Also removed the 'filter by' option at
the top of the search results if there is only one type of record in the found set.
- Fixed error in IE when clicking '+' sign next to record in list view - undefined variable
df_add_editable_awareness
shannah
 
Posts: 4457
Joined: Wed Dec 31, 1969 5:00 pm

Re: Xataface 1.3rc3 Released

Postby PaulR » Sun May 22, 2011 6:39 am

- Added IP address check in the session to prevent people from spoofing sessions

Does this mean that users who are not on a static IP address will always need to log out or clear cookies at the end of each session? If so, is it possible to 'turn off' this feature? (If it presents a serious security risk then of course I could live with it!)

Paul
PaulR
 
Posts: 19
Joined: Tue May 17, 2011 10:38 pm

Re: Xataface 1.3rc3 Released

Postby jackch » Sun Jun 12, 2011 8:29 pm

cool,i like it
jackch
 

Re: Xataface 1.3rc3 Released

Postby ADobkin » Tue Jul 19, 2011 8:45 pm

>- Added IP address check in the session to prevent people from spoofing sessions
>
>Does this mean that users who are not on a static IP address will always need to log out or clear cookies at the end of each session? If so, is it possible to 'turn off' this feature? (If it presents a serious security risk then of course I could live with it!)
>
>Paul

The other new features in 1.3 are very welcome, but I don't see the value in this one the way it works now. As PaulR implied, since updating to 1.3rc3, Xataface throws the following error message every time my IP address changes:

>Your IP address doesn't match the session address. To continue, please clear your cookies or restart your browser and try again.

I often access my site from an iPad or other mobile device, and the IP changes every time my location changes, which makes it very difficult to stay connected. Clearing cookies or restarting a browser every time this happens has other implications when the user has many tabs open with dynamic sessions to other sites. Further, it doesn't seem to prevent someone else from spoofing the session if all they have to do is clear their session cookie or restart their browser. Granted, if two people are actively trying to share the same session ID at the same time, that would be a problem. But is just as likely that the "bad guy" session is active on a different IP while the "good guy" session is idle and unaware of the hijacking.

As PaulR requested, can this feature be disabled, such as in conf.ini? Or is there a better recommendation to solve the problem with changing IP addresses?

BTW, I also noticed that 1.3 now seems to enforce a lower-case (or case-sensitive) username at the login prompt. Prior, we often used mixed-case usernames, so the saved logins stopped working recently. Is this another security feature, and can it also be controlled by a config option?

One last question related to login security issues: Can we have an option to set an automatic login (session cookie) idle timeout on a per-user basis? For example, I would log out certain user accounts after 10-15 minutes of inactivity. I think this would be a more effective security measure than the IP address check, since the session would no longer exist when not actively in use.

Thanks,
Alan
ADobkin
 
Posts: 195
Joined: Mon Oct 22, 2007 7:31 pm
Location: Atlanta, GA, USA


Return to Xataface News

Who is online

Users browsing this forum: No registered users and 5 guests

cron
Powered by Dataface
© 2005-2007 Steve Hannah All rights reserved