Bug 570864 - Review Request: drupal-securepages_prevent_hijack - Secure Pages add-on that prevents hijacked sessions from accessing SSL pages
Summary: Review Request: drupal-securepages_prevent_hijack - Secure Pages add-on that ...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Sven Lankes
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 570862
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-03-05 17:39 UTC by Orion Poplawski
Modified: 2012-12-19 03:21 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2012-12-19 03:21:29 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Orion Poplawski 2010-03-05 17:39:11 UTC
Spec URL: http://www.cora.nwra.com/~orion/fedora/drupal-securepages_prevent_hijack.spec
SRPM URL: http://www.cora.nwra.com/~orion/fedora/drupal-securepages_prevent_hijack-6.x.1.5-1.fc12.src.rpm

Description:
This is an add-on to the Secure Pages module that will prevent hijacked
sessions from accessing SSL pages, yet still allow users to stay logged in
when browsing non-SSL pages.

The login form is also secured, both on the user page and the login block.

This module is recommended for most securepages users. (One possible
exception is if you have set session.cookie_secure, and you have "Switch back
to http" disabled in the securepages settings.)

Please do consider carefully the inherent limitations of mixed HTTP / HTTPS
sessions. For an analysis of various approaches to using SSL, see this[1]
article on crackingdrupal.com.

[1] - http://crackingdrupal.com/blog/greggles/drupal-and-ssl-multiple-recipes-possible-solutions

Comment 1 Sven Lankes 2010-11-19 15:04:12 UTC
After some discussion on the fedora-logistics list, we've come to the 
conclusion that having the possibility to install multiple concurrent versions of drupal is desirable. 

The drupal-package is going to be renamed to drupal6 (rename review is pending).

Additionally, the guidelines don't allow letters in the version (so no 6.x) - so please rename the package to drupal6-securepages_prevent_hijack-1.5.

Once that is done, I'll do the review.

Comment 3 Volker Fröhlich 2011-01-18 13:57:37 UTC
Please correct the license to GPLv2+, as all modules hosted in Drupal's CVS must be.

Comment 4 Miroslav Suchý 2012-12-16 12:53:09 UTC
Ping? Any progress here? Or we can close this review?

Comment 5 Orion Poplawski 2012-12-19 03:21:29 UTC
Let's close.


Note You need to log in before you can comment on or make changes to this bug.