Allow log-in via URL link
Posted: 05 June 2008 05:51 AM   [ Ignore ]  
Summer Student
Total Posts:  20
Joined  04-03-2008

It would be great if it were possible for the system to accept $ _GET variables for log-in.

This would allow new members to log in from the new member email like this:

http://yourEEsite.com/?ACT=9&username=sue&password=123123

Perhaps a CP setting could be added ‘Allow URL login’…

Profile
 
 
Posted: 05 June 2008 08:13 AM   [ Ignore ]   [ # 1 ]  
Lab Assistant
Avatar
RankRank
Total Posts:  172
Joined  05-15-2004

That seems like it would be horribly insecure.

 Signature 

AKA Chris Simmons

Profile
 
 
Posted: 15 June 2008 06:01 PM   [ Ignore ]   [ # 2 ]  
Summer Student
Total Posts:  20
Joined  04-03-2008

Evil Spy: I don’t think it it would be any less secure than the current method, unless you have your site set up to use https (and thus member login info is encrypted when sent)

I have looked at mod.member_auth.php and it seems it it would be a simple matter of catching either the $POST or $GET login info and then assigning it to local variables for login purposes…

Could we please get some feed back from EE about this?  There are posts from other users wanting the same functionality.

thanks

Profile
 
 
Posted: 15 June 2008 09:23 PM   [ Ignore ]   [ # 3 ]  
Administrator
Avatar
RankRankRankRankRankRankRank
Total Posts:  15826
Joined  06-03-2002

GET is not innately less secure than POST, as either can be manipulated, sniffed, etc., but in the case of logins, no, we will not be adding GET support.  Consider people using EE from public terminals.  Their entire site could be compromised from accidentally leaving the link in the browser history after logging out.

 Signature 
Profile
MSG
 
 
Posted: 16 June 2008 12:34 AM   [ Ignore ]   [ # 4 ]  
Lab Assistant
Avatar
RankRank
Total Posts:  246
Joined  04-12-2008

You could still start playing around with this for your purposes using EE hooks, you might have a look at ‘login_authenticate_start’

 Signature 

Designchuchi | Twitter

URL Field Extension
Required Category Extension
DC FreeForm GeoIP Extension

Profile
 
 
Posted: 16 June 2008 09:46 AM   [ Ignore ]   [ # 5 ]  
Lab Assistant
Avatar
RankRank
Total Posts:  172
Joined  05-15-2004
Derek Jones - 15 June 2008 09:23 PM

GET is not innately less secure than POST, as either can be manipulated, sniffed, etc., but in the case of logins, no, we will not be adding GET support.  Consider people using EE from public terminals.  Their entire site could be compromised from accidentally leaving the link in the browser history after logging out.

That’s the particular case I was thinking of, actually. Basically leaving your username and password pair in your browser’s history seems like a bad idea.

 Signature 

AKA Chris Simmons

Profile
 
 
   
 
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 1149, on July 16, 2007 09:33 AM
Total Registered Members: 64909 Total Logged-in Users: 44
Total Topics: 81854 Total Anonymous Users: 28
Total Replies: 440068 Total Guests: 222
Total Posts: 521922    
Members ( View Memberlist )