Re: [pgsql-www] Google signin

Поиск
Список
Период
Сортировка
От Daniel Gustafsson
Тема Re: [pgsql-www] Google signin
Дата
Msg-id 9AE33E9B-A024-4113-98A0-7F395E2A917E@yesql.se
обсуждение исходный текст
Ответ на Re: [pgsql-www] Google signin  (Magnus Hagander <magnus@hagander.net>)
Ответы Re: [pgsql-www] Google signin  (Magnus Hagander <magnus@hagander.net>)
Список pgsql-www
> On 15 Aug 2017, at 12:18, Magnus Hagander <magnus@hagander.net> wrote:
>
> Here's an updated patch

In the below hunk, s/decicated/dedicated/:

+a decicated account, or use one of the third party sign-in systems below.

Without being terribly well versed in Django (or Python), the logic seems quite
reasonable to me on a read through/review.

> that does this. It will try in order:
> <firstname><lastinitial>, e.g. stephenf
> <firstinitial><lasdtname>,e.g. sfrost
> <firstname><lastinitial><number>, e.g. stephenf0, stephenf1, stephenf2 etc

How about a random number instead?  Not that I see any immediate risk with
anything here, but many years of looking at logs from web attacks has taught me
that predictability is what is being tried first.

A big +1 on getting this functionality in.

cheers ./daniel




В списке pgsql-www по дате отправления:

Предыдущее
От: Stephen Frost
Дата:
Сообщение: Re: [pgsql-www] Google signin
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: [pgsql-www] Google signin