Admin can display another username Admin can display another username
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

Admin can display another username

Started by isajade, December 14, 2007, 03:55:15 PM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

isajade

To prevent malicious attemps, will it be possible to have an option for the administrator to display on the gallery a different username than the one used to log in. Thank you.

Joachim Müller

Using a non-trivial password that is long enough should keep you save of brute-force attacks.

isajade

Is there a maximum length? I had a 11  characters password that I changed to a 27 characters long and I get an error message.

Joachim Müller

Afaik the max number of characters for the password field is set to 40, so you should be good. 27 chars is not needed imo, I'd go for 14 chars.
There is no support in the feature requests sub-board.

isajade

#4
Ho oupsy about that, I didn't mean to.
Thank you for your reply.

TigerClaw

Apart from security (useless as explained), it can be helpfull for privacy concerns: Don't show to the general visitor that admin has uploaded that file.

Joachim Müller

Well, then don't name your user account "admin" or "master_of_disaster", but just "fred_jones" - nobody will then know (just by looking at the username) that a file has been uploaded by the admin. Additionally, I can't see what is suppossed to be so bad about the fact that site users can see who uploaded a file.

TigerClaw

Quote from: Joachim Müller on January 31, 2008, 08:43:42 AM
Well, then don't name your user account "admin" or "master_of_disaster", but just "fred_jones" - nobody will then know (just by looking at the username) that a file has been uploaded by the admin. Additionally, I can't see what is suppossed to be so bad about the fact that site users can see who uploaded a file.

True, but sometimes you just don't think about it before starting, you work on the gallery and you remain with "admin" which is not very cool. For example you suggested "Master of Disaster" that I want as my username on the gallery NOW!  ;D

Joachim Müller

Go ahead an create another admin account that is named that way.