GHF Census and Excise Office #2

Post » Fri May 27, 2011 5:12 am

I've fixed a few display bugs, such as the blank boxes where characters should be displayed. Also added a display of how long since the character was last updated. Right now they are all the same since I had to put a default time in the database. (I'm pretty proud of that display function actually!)

Peachy is working on the uploading bug; he'll have it finished in no time!

Oh yeah, I'll work on the avatar upload tomorrow. :P
User avatar
Sweet Blighty
 
Posts: 3423
Joined: Wed Jun 21, 2006 6:39 am

Post » Fri May 27, 2011 3:03 pm

I've fixed a few display bugs, such as the blank boxes where characters should be displayed. Also added a display of how long since the character was last updated. Right now they are all the same since I had to put a default time in the database. (I'm pretty proud of that display function actually!)

Peachy is working on the uploading bug; he'll have it finished in no time!

Oh yeah, I'll work on the avatar upload tomorrow. :P

yeah, everyones pin are shown now and everything is really big
User avatar
Siobhan Thompson
 
Posts: 3443
Joined: Sun Nov 12, 2006 10:40 am

Post » Fri May 27, 2011 2:42 am

uhm...Fligg..you might want to take a look http://img38.imageshack.us/img38/7450/35457631.jpg :unsure:
User avatar
StunnaLiike FiiFii
 
Posts: 3373
Joined: Tue Oct 31, 2006 2:30 am

Post » Fri May 27, 2011 1:57 pm

I've fixed that bug.
User avatar
Kara Payne
 
Posts: 3415
Joined: Thu Oct 26, 2006 12:47 am

Post » Fri May 27, 2011 6:11 pm

I've created a full debug build of CnE (which will not be released) and located the bug! :D
Fixing now.
User avatar
mike
 
Posts: 3432
Joined: Fri Jul 27, 2007 6:51 pm

Post » Fri May 27, 2011 11:16 am

I had this problem before but now the dates are messed up. I did NOT creat them all on the same day and defenitley not at the same time ( minute )
http://s886.photobucket.com/albums/ac69/Wolf3131/?action=view¤t=Untitled.jpg&t=1249319851115
User avatar
Sierra Ritsuka
 
Posts: 3506
Joined: Mon Dec 11, 2006 7:56 am

Post » Fri May 27, 2011 7:43 am

I had this problem before but now the dates are messed up. I did NOT creat them all on the same day and defenitley not at the same time ( minute )
http://s886.photobucket.com/albums/ac69/Wolf3131/?action=view¤t=Untitled.jpg&t=1249319851115

Where's my magnifying glass?? ;)

Don't worry about the dates, it is a new feature that will work for new characters made from now on. All previous characters will appear to have been made when this feature was implemented.
Same with the "last updated" feature. Once the update works again, it will change accordingly.
User avatar
Francesca
 
Posts: 3485
Joined: Thu Jun 22, 2006 5:26 pm

Post » Fri May 27, 2011 2:55 am

Aright. I think the update should be working again (try it).
At the moment, you'll receive an "error" (unknown error). I need to fix that on the code side.
As long as you see:
Reply: 127Updated character and gallery.

in the console, it should be working. I'll go over it again and check, but I think I fixed it.

Edit: checked, and my char is up, with correct skills. Everyone else, please chime in as you update and see if it's working.
User avatar
Nicholas
 
Posts: 3454
Joined: Wed Jul 04, 2007 12:05 am

Post » Fri May 27, 2011 12:14 pm

Everyone else, please chime in as you update and see if it's working.

I just successfully updated my character, and all my info looks correct.

"Last Updated" still remains at default.
User avatar
Kate Norris
 
Posts: 3373
Joined: Mon Nov 27, 2006 6:12 pm

Post » Fri May 27, 2011 5:37 pm

I got my 4th character on manage characters and they all dont work :P ( this uploader gave me an unknown error report )

But for some reason it worked... heh i need a delete button fligg could you delete all but one of my level 19's
User avatar
Soph
 
Posts: 3499
Joined: Fri Oct 13, 2006 8:24 am

Post » Fri May 27, 2011 11:47 am

Aright. I think the update should be working again (try it).
At the moment, you'll receive an "error" (unknown error). I need to fix that on the code side.
As long as you see:
Reply: 127Updated character and gallery.

in the console, it should be working. I'll go over it again and check, but I think I fixed it.

Edit: checked, and my char is up, with correct skills. Everyone else, please chime in as you update and see if it's working.

Upload success for me :goodjob:
User avatar
louise fortin
 
Posts: 3327
Joined: Wed Apr 04, 2007 4:51 am

Post » Fri May 27, 2011 4:22 am

Aright. I think the update should be working again (try it).
At the moment, you'll receive an "error" (unknown error). I need to fix that on the code side.
As long as you see:
Reply: 127Updated character and gallery.

in the console, it should be working. I'll go over it again and check, but I think I fixed it.

Edit: checked, and my char is up, with correct skills. Everyone else, please chime in as you update and see if it's working.

Skill stats are working now. :goodjob:
But health, magicka and fatigue stats are still http://img197.imageshack.us/img197/5460/unbenannt1wvz.jpg.
User avatar
~Amy~
 
Posts: 3478
Joined: Sat Aug 12, 2006 5:38 am

Post » Fri May 27, 2011 12:55 pm

Thanks for sorting that out Peachy. :goodjob:

The update time feature was actually much of the issue (it IS my first time working with time/date functions in PHP...weird stuff.) I'll fiddle with it a bit more and ensure it all updates properly when I get home tonight.
User avatar
Bek Rideout
 
Posts: 3401
Joined: Fri Mar 02, 2007 7:00 pm

Post » Fri May 27, 2011 3:21 am

Actually, I forgot that I wanted to comment a bit on the display problem we had earlier.

I want to reassure you all that having the PINs visible is not really a security breach. Knowing someone's PIN will not let you hack into their account or anything like that. At most they can overwrite the character information that is submitted by the uploader program. And that is very easily remedied. And knowing that this is a test environment, I have taken precautions to avoid any truly sensitive data from becoming available.

We will, however, be implementing another layer of security. After the events caused by a pathetic hacker at GHF last year I have become rather paranoid about web security. Not only are we using traditional PHP and MySQL security methods, restricted referrer access and other server side controls, I have developed a sort of encryption that will be implemented in the MWSE scripts.

So don't worry about any vulnerabilities. I'm all over it. :goodjob:
User avatar
Dean Brown
 
Posts: 3472
Joined: Fri Aug 31, 2007 10:17 pm

Post » Fri May 27, 2011 2:56 am

All hail fliggerty!
User avatar
Georgine Lee
 
Posts: 3353
Joined: Wed Oct 04, 2006 11:50 am

Post » Fri May 27, 2011 4:43 pm

Off-topic are you still working on Better battles?

On-topic When is this closed beta testing?
User avatar
Elisabete Gaspar
 
Posts: 3558
Joined: Thu Aug 31, 2006 1:15 pm

Post » Fri May 27, 2011 4:02 am

.
User avatar
Christie Mitchell
 
Posts: 3389
Joined: Mon Nov 27, 2006 10:44 pm

Post » Fri May 27, 2011 12:45 pm

I want to reassure you all that having the PINs visible is not really a security breach. Knowing someone's PIN will not let you hack into their account or anything like that. At most they can overwrite the character information that is submitted by the uploader program. And that is very easily remedied. And knowing that this is a test environment, I have taken precautions to avoid any truly sensitive data from becoming available.

We will, however, be implementing another layer of security. After the events caused by a pathetic hacker at GHF last year I have become rather paranoid about web security. Not only are we using traditional PHP and MySQL security methods, restricted referrer access and other server side controls, I have developed a sort of encryption that will be implemented in the MWSE scripts.

So don't worry about any vulnerabilities. I'm all over it. :goodjob:


In addition, our security has been tested once and held up just fine. There are a few more simple layers in place now, and Fligg's adding some complicated stuff.
Plus, I'm plotting tests for it. ;)

On-topic When is this closed beta testing?


The beta will come after the alpha, but before final release.
User avatar
Sara Lee
 
Posts: 3448
Joined: Mon Sep 25, 2006 1:40 pm

Post » Fri May 27, 2011 10:50 am

Off-topic are you still working on Better battles?

Technically, yes. I've been focusing on CnE lately though obviously. Don't worry, this is how I always do things. I have to jump from one project to another when I have ideas and motivation. ;)

On-topic When is this closed beta testing?

Like Peachy said, after ALPHA testing. Before GAMMA testing. And WAAAAAY before ZETA testing.

Here's the basic project "timeline" breakdown that I've had planned:

1. Build core functionality.
2. Begin ALPHA test (this will continue until the next testing phase begins.)
3. Add additional features and function (the "bells and whistles" phase.)
4. Begin BETA testing phase.
5. "Polish" the appearance and add mod support.
6. Release.

We are now on #3.


Plus, I'm plotting tests for it.


Bring it on!
User avatar
Sammykins
 
Posts: 3330
Joined: Fri Jun 23, 2006 10:48 am

Post » Fri May 27, 2011 1:24 pm

Well, don't rush it because anyone wants it NOW.
If steps #3 #4 and #5 each take a month, so be it :)

(but I can't wait for the Zeta release. That's gotta be awesome!)
User avatar
Manny(BAKE)
 
Posts: 3407
Joined: Thu Oct 25, 2007 9:14 am

Post » Fri May 27, 2011 11:09 am

I got bored (It was taking ages, as I had large gaps between the requests). FYI I don't think Fliggs pin is anything under 2458... You should try and do something to stop brute force attacks. Stopping anyone updating a character (and refusing to give any error except for a message like 'Banned') for 2 mins if they got the ID wrong 3 times would do it.

Also, what is the point of hiding the implementation of the MWSE code? It is far to far away from the server to do anything with. 20 Seconds with a packet sniffer showed me where you were sending the data and in what format.



Oh... And the program works fine under Wine :). It would be nice if the program printed the error messages from the server though. I didn't set the id correctly, so got a error message from the program that didn't tell me anything, but the server responded with '114Invalid character!', which tells me I have got the character id wrong
'
User avatar
Céline Rémy
 
Posts: 3443
Joined: Sat Apr 07, 2007 12:45 am

Post » Fri May 27, 2011 3:05 pm

Most of the real security stuff isn't implemented yet. :P This is just ALPHA.... ;)

We're not hiding the MWSE code or anything. What we are doing is....complicated. I wanted to ensure that someone couldn't just write something and up some bogus data with cURL and try to attack in that way. I'm not going to go into any detail here (the less the public knows the better.) But I'd gladly explain it over PM if you are curious...assuming you pass the FBI background check that is.
User avatar
мistrєss
 
Posts: 3168
Joined: Thu Dec 14, 2006 3:13 am

Post » Fri May 27, 2011 6:52 am

I was wondering how you'd deal with mods such as TR and race mods, possibly when showing player location (on a map perhaps?)
User avatar
Steph
 
Posts: 3469
Joined: Sun Nov 19, 2006 7:44 am

Post » Fri May 27, 2011 9:32 am

I got bored (It was taking ages, as I had large gaps between the requests). FYI I don't think Fliggs pin is anything under 2458... You should try and do something to stop brute force attacks. Stopping anyone updating a character (and refusing to give any error except for a message like 'Banned') for 2 mins if they got the ID wrong 3 times would do it.


I was benchmarking brute forces the other day, and it would certainly have to be server-side. My crappy comp ran through all possible PINs in under a minute. I think, adding 5 seconds per, it would be an overnight deal. Even MD5ing them first doesn't slow it down much.

Also, what is the point of hiding the implementation of the MWSE code? It is far to far away from the server to do anything with. 20 Seconds with a packet sniffer showed me where you were sending the data and in what format.


We're not hiding the data, only verifying (to a limited extent) it's not being sent from any other source, especially forms on the web.



Oh... And the program works fine under Wine :) . It would be nice if the program printed the error messages from the server though. I didn't set the id correctly, so got a error message from the program that didn't tell me anything, but the server responded with '114Invalid character!', which tells me I have got the character id wrong
'

Don't worry there, I have the code for that 3/4 done. Certain messages return right, some don't. I'm working on making them all work.


Most of the real security stuff isn't implemented yet. :P This is just ALPHA.... ;)

We're not hiding the MWSE code or anything. What we are doing is....complicated. I wanted to ensure that someone couldn't just write something and up some bogus data with cURL and try to attack in that way. I'm not going to go into any detail here (the less the public knows the better.) But I'd gladly explain it over PM if you are curious...

It's more for forms, people trying to submit characters that way. But it would stop alternate client apps too. Security I'm mostly leaving to Fligg.

assuming you pass the FBI background check that is.

Is that the one that makes sure you're a kid? :P


I was wondering how you'd deal with mods such as TR and race mods, possibly when showing player location (on a map perhaps?)


Race mods aren't a problem, it will still work with thos.
I don't know why TR would cause any problems, though. Elaborate?
User avatar
Jason Wolf
 
Posts: 3390
Joined: Sun Jun 17, 2007 7:30 am

Post » Fri May 27, 2011 6:06 pm

Just had to say that I think this is pure brilliance, it's a fantastic idea and I think it will make the morrowind community survive all that much longer, witch is a very good thing.

Always hoped there would be something like this eventually =)

It is always interesting to read about others characters and what they achieved with them, and this will probably make that one part so much greater and bigger.

absolutely amazing =)

Good work to everyone working on this!
User avatar
Emma Pennington
 
Posts: 3346
Joined: Tue Oct 17, 2006 8:41 am

PreviousNext

Return to III - Morrowind