|
|
Tachyon
DOOP Secretary
|
|
Yeah, there are some issues with features and some mostly cosmetic stuff. But the important thing is that it's up and running and people are able to post.
|
|
|
|
|
winna
Avatar Czar
DOOP Ubersecretary
|
|
|
« Reply #43 on: 04-09-2021 07:14 »
« Last Edit on: 04-09-2021 07:34 »
|
|
I'm glad it's still here. Not having a phone for most of last year kind of sucked in some ways, and I wondered how you were all doing. Plus I wanted to relay my adventures when I wasn't personally fighting off death for weeks at a time, but most of those tales are far too beyond believing, and though I visit the houses of strangers to mark the examples in their bibles, it's hard for a lot of people to accept the wisemen were feeding crystal meth to baby Jesus. That's before I show them Jesus' personal hadoken, the Rebuken! 🄯 or his dragonball z move, The Starscream🄯 and they still have their doubts. What kind of carpenter is proficient with a whip though? And who flips the pages in the wind when you ask a question? He probably has a spirit bomb too, and I haven't even seen a depiction of that yet....not that the one where he turns his head into a bullhorn isn't a powerful enough weapon, especially since the Word of God literally poured out of his mouth. Oh cool, I just remembered why my ubb codes weren't working, they don't use the html vector brackets. I realized that glass sphere with 7 points of light seemed a bit odd during another experience no one would believe me about (true event that absolutely really did happen): turns out the experts realized da vinci painted it truthfully toward reality if that glass sphere isn't solid, it's hollow. He was always saying, "my piece be with you...". I just didn't realize he meant his 9mm or his glass bowl for not smoking drugs out of. What would really blow your mind is if I told you those two hand arrangements, when brought together spell out the law he taught about, which presumably he enforced with one or both of those pieces. I'll take a picture later, and you can tell me ,"No fucking way" later.
|
|
|
|
|
Farnsworth38
Professor
|
|
Was it just me, or was the site playing up earlier? I wondered if there was another update underway, or perhaps an attack.
|
|
|
|
|
Svip
Administrator
DOOP Secretary
|
|
|
« Reply #45 on: 06-04-2021 09:03 »
« Last Edit on: 06-04-2021 09:23 »
|
|
Yes, I saw. I am still not entirely sure what happened, but apparently someone is abusing the /cgi-bin/ scripts on the server. Or at least attempting to. And I am generally considering removing the out.cgi bits entirely. On their own, they should not be too severe, although since it modifies a browser's referer record, it can be used to 'tunnel' traffic through the server to more unbecoming of sites. And it does not appear to me that there is any purpose to the out.cgi script anyway.
Edit: Yes, it appears newer versions of SMF don't use the out.cgi anymore, and it was mostly rendered upon load anyway (that is; it was not straight in the database). It did appear in 126 posts in total, so I modified those in the database to not use the out.cgi script. This should also give linking a generally more smooth experience, and others cannot abuse the script for their own purposes.
So yes, basically an attack. My hope is, now that I have removed the script, and they are now just getting 404 errors, the attempts will subside soon. But it may take a while for them to catch up.
|
|
|
|
|
|
|
Svip
Administrator
DOOP Secretary
|
|
I would still need to find the time to get it up and running, even if someone else fixed the files. It's not that big of a job, I just need to get off my ass and do it. Unfortunately, whenever I feel up for it, I have other more pressing things to do. Hopefully I can get an opportunity this month. But I keep saying that to myself.
As for wikiPEELia, it is not lost. I have all the data, I just need to get it up and running as well.
|
|
|
|
|
|
|
Gorky
DOOP Secretary
|
|
Thanks for all your work on this, Svip! Just a note on PMs: while I can see from the PEEL homepage that I have a new message, and can access my PM inbox, I can't actually open any of my PMs; I click the subject-line link for the individual message and it goes nowhere. (I'm not sure if this is what you're referring to in the second paragraph of your post, but wanted to call attention to the issue just in case.)
|
|
|
|
|
|
|
|
Svip
Administrator
DOOP Secretary
|
|
Awesome sauce!
Is there some reason you can't pass the message number as a string?
The problem is that the number is just a number, but what it references is gone, and been replaced by a named string. So 515 has been renamed to 'by'. So I need to track down these renamings, and that's what's taking time.
|
|
|
|
|
Tachyon
DOOP Secretary
|
|
We're very glad to have Peel back, and appreciate that you've adopted it and are working out the kinks caused by updating the software.
|
|
|
|
|
winna
Avatar Czar
DOOP Ubersecretary
|
|
Awesome sauce!
Is there some reason you can't pass the message number as a string?
The problem is that the number is just a number, but what it references is gone, and been replaced by a named string. So 515 has been renamed to 'by'. So I need to track down these renamings, and that's what's taking time.
What are the chances of finding the original function that handled that, adding that function in, then casting the return from that function? I wouldn't be surprised if [-mArc-] customized that particular portion while he was transmigrating data to PEEL 2; it's a little presumptuous of me, but do you have one of the original backups lying around somewhere? I would think there's a work around of some kind there--the back-end is all php if I recall correctly (at some point, I spent a lot of time studying phpbb builds and the smf packages), so it seems like it should be possible to modify in a quick solution. I won't ask again though, because you're far more knowledgeable than I am in that arena, Svip, and although I oft enjoy tedious tasks, I appreciate the gravity of the Herculean task you're discussing. Thank you for mending the private messages, Svip; works great for me so far. As an aside, you might want to look into and verify that the account password submissions are properly salted. No reason I mention that.
|
|
|
|
|
Svip
Administrator
DOOP Secretary
|
|
The larger problem was these translations were not located in the same place, if they are all available. I am also concerned whether some were stored in the database, rather than PHP files, since not all of them are included in the PEEL theme language files.
I recognised I could mostly have covered it by simply loading in some old code, but I decided against that - even if it would have worked and quickly at so - because I wanted a long term solution. Put another way; it may work for now, but will it work when we upgrade SMF again?
And yes, I have actually checked that passwords are salted, hashed and stored properly.
|
|
|
|
|
|
Svip
Administrator
DOOP Secretary
|
|
Hm, I haven't really gotten to the profile edit screens yet. But like I said, there is still stuff remaining. At least now I know I will prioritise the profile edit screens and in particular avatar changing screens next.
|
|
|
|
|
|
|
|
|
|