design5 at softflow.co.uk
Sun May 18 13:41:00 CDT 2008
Sunday, May 18, 2008, 5:32:09 PM, Hans wrote:
> But then I discovered I could register as a
> new News Master! And after registering I could log in.
> So this does not seem to be secure either.
The micro_login_system allows a new user to register creating a new
user name and encrypted password.
I think this needs to be disabled. There should be no register
link, and the registerUser function in common.php should be disabled.
Still this leaves a little problem adding new NewsMasters: username
and md5 encrypted password needs to be added to userpwd.txt.
More information about the pmwiki-users