Jump to content
  • 0

Account validation broken


g96968

Question

When creating a new account, forum.step-project.com is sending the following validation link:

https://forum.step-project.com/index.php?app=core&module=global§ion=register&do=05

 

where it should be:

https://forum.step-project.com/index.php?app=core&module=global&section=register&do=05

 

Similarly, the auto validation link is broken:

https://forum.step-project.com/index.php?app=core&module=global§ion=register&do=auto_validate&uid=xxxx&aid=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

 

but it should be:

https://forum.step-project.com/index.php?app=core&module=global&section=register&do=auto_validate&uid=xxxx&aid=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

 

Finally, the https interface is open with a bad certificate and an admin management access. Even if you don't care about secure access, you should at least close down that interface since it's a separate running instance. Alternatively if you're using it for admin operations you should assign a non-default port so it won't get accessed by mistake.

Link to comment
Share on other sites

4 answers to this question

Recommended Posts

  • 0

This looks like an HTML decoding bug in the email service or the email client. Specifically, § is the HTML encoded version of the section sign (§) and the translation should occur only when the encoding begins with an ampersand and ends with a semicolon. In this case, the software is erroneously replacing &sect with section sign even though &sect is not a valid HTML encoding and should not be translated.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Guidelines, Privacy Policy, and Terms of Use.