ajwecker / TS1218

Tikkoun Sofrim crowd sourcing interface
0 stars 4 forks source link

Security issues http->https #70

Open MosheLavee opened 5 years ago

MosheLavee commented 5 years ago

What is the state of the security issues Alan mentioned today ? were they done.

  1. בתור התחלה, תאבטחו את השרת ושלפחות ה login יהיה ב HTTPS ולא ב HTTP. feed back I got from a user - image
ajwecker commented 5 years ago

https this Uri and I think was done for register and addtransaction. I used prepared statement. Only think left is protecting input fields from bad html I will do later as my wife car battery died

On Mon, Feb 11, 2019, 9:02 PM MosheLavee <notifications@github.com wrote:

What is the state of the security issues Alan mentioned today ? were they done.

  1. בתור התחלה, תאבטחו את השרת ושלפחות ה login יהיה ב HTTPS ולא ב HTTP. feed back I got from a user - [image: image] https://user-images.githubusercontent.com/6770031/52586409-1e247080-2e40-11e9-88a6-9cf72dda8769.png

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/ajwecker/TS1218/issues/70, or mute the thread https://github.com/notifications/unsubscribe-auth/AAcwDQMKKedRR-RxEXSpgg8A8Ud8Te18ks5vMb41gaJpZM4a0187 .

dstoekl commented 5 years ago

if I am not mistaken this is the logical answer if you dont use the prefix https://.... not our fault.

MosheLavee commented 5 years ago

@ajwecker @dstoekl @drore @TsvikaKuflik @urischor Hi - people are saying that we must do that if anyone put http it would automatically changed to https. There are wonderful resoponses on Fascebook but this specific issue is highly urgent!

MosheLavee commented 5 years ago

@urischor assigned to you.