Personal log links are FUBAR

Locked
RobinInDaHood
Forum Elite
Posts: 1509
Joined: Wed Oct 25, 2006 3:39 am
Race: Vulpes
ID: 75697
Location: Da Hood, of course

Personal log links are FUBAR

When typing a link to the stats page of a user in the personal log, the http: is being replaced with link:. This causes Firefox to throw a message stating that no program is associated with link:.

Here's an example of what I typed:

<a href="http://www.stargatewars.com/stats.php?id=37162">37162</a>

And it gets mangled into:

<a href="link://www.stargatewars.com/stats.php?id=37162">37162</a>

Please fix. I use the personal log all the time for my raiding list.
DaDigi
Forum Elder
Posts: 2358
Joined: Sun Nov 27, 2005 11:29 am
Alliance: I hate all equally
Race: Tri-athalon
ID: 46811
Location: Philadelphia, PA
Contact:

Re: Personal log links are FUBAR

I believe that was put into effect to curve any hacking attempt using the log...
DaDigi
Former Moderator for Market & Suggestions/Reports
pc
Fledgling Forumer
Posts: 239
Joined: Mon Dec 11, 2006 8:45 am

Re: Personal log links are FUBAR

RobinInDaHood wrote:When typing a link to the stats page of a user in the personal log, the http: is being replaced with link:. This causes Firefox to throw a message stating that no program is associated with link:.

Here's an example of what I typed:

<a href="http://www.stargatewars.com/stats.php?id=37162">37162</a>

And it gets mangled into:

<a href="link://www.stargatewars.com/stats.php?id=37162">37162</a>

Please fix. I use the personal log all the time for my raiding list.

Use:
<a href=stats.php?id=37162>37162</a><br />

or

<a href=stats.php?id=37162>37162<br />
Image
Image
RobinInDaHood
Forum Elite
Posts: 1509
Joined: Wed Oct 25, 2006 3:39 am
Race: Vulpes
ID: 75697
Location: Da Hood, of course

Re: Personal log links are FUBAR

DaDigi wrote:I believe that was put into effect to curve any hacking attempt using the log...


Perhaps, but it altered existing entries in the log as well as those that I had been adding. If Jason thinks that converting "http" to "link" will thwart hacking attempts, he's needs to spend some time with a few development books and learn proper coding techniques. SQL and HTML injection can be 100% solved in PHP with the addition of TWO (2) lines of code to your script.

I guess I'll go through the couple thousand entries and edit them to fit another, more "secure" format. :lol: /sigh
Locked

Return to “Bugs Archive”