Relationship Request Bug

Welcome furry fans!

We're glad you stopped by. Go ahead and register for a free account to get the benefits of being a member, including:
  • Access to all of our posts and comments
  • Your own profile including an avatar, buddy lists, and other social networking features
  • The ability to participate in a community of over 8,000 furry fans!
Creating an account is easy. Register now!
6 replies [Last post]
Protocollie's picture
This user is a Staff Member
Location: Philadelphia, PA
"Con Chair. (That means you're not allowed to move me.)"
Posts: 1277
Votes Received:
4.5
490 votes received
Buddy List

Giza,

Someone added me as a buddy on here and so I have this little white bar at the top of my screen telling me. If I try and click 'approve', a dialog pops up with a little spinner that says form loading and... that's it. Tried it on three different machines, chrome/firefox/IE and on two different internet connections. No dice.

Just wanted to let you know!

0
No votes yet
Your rating: None

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Giza's picture
This user is a Board MemberThis user is a Staff Member
Location: Ardmore, PA
"Webmaster Leopard"
Posts: 2754
Votes Received:
4.6
1693 votes received
Buddy List

I think it might be a byproduct of the SSL I recently enabled on user pages.

But I'll need to reproduce it, first. Since I'm not currently on your buddy list, can you add me so I can get the request and try to reproduce the issue?

Also, did the buddy request go through successfully even though things appeared to hang on you rbrowser?

0
No votes yet
Your rating: None

Pennsylvania Furry? Be sure to check out http://www.pa-furry.org/

Unclekage's picture
This user is a Board MemberThis user is a Staff Member
Posts: 3419
Votes Received:
4.7
2458 votes received
Buddy List

That's just a cheap way to get people to add you to their buddy lists. Shame on you!

0
No votes yet
Your rating: None
Protocollie's picture
This user is a Staff Member
Location: Philadelphia, PA
"Con Chair. (That means you're not allowed to move me.)"
Posts: 1277
Votes Received:
4.5
490 votes received
Buddy List

Will do, and no, it hasn't gone through and the bar won't go away.

0
No votes yet
Your rating: None
Giza's picture
This user is a Board MemberThis user is a Staff Member
Location: Ardmore, PA
"Webmaster Leopard"
Posts: 2754
Votes Received:
4.6
1693 votes received
Buddy List

Okay, I was able to reproduce it, and fixed the issue.

As I suspected, the "relationships" page was HTTP, and the URL that it was trying to communicate with via AJAX was HTTPS. Seems reasonable enough, but it turns out that if a browser allowed encrypted content to be loaded via AJAX (on an unencrypted page), it puts the user at risk of a "session renegotiation attack".

More info on why FireFox (and other browsers) acted the way they did can be found at https://wiki.mozilla.org/Security:Renegotiation.

The fix, BTW, was for me to tweak the settings from the Securepages module to have the relationships page loaded securely. A page loaded via SSL making an AJAX call to SSL content on the same domain is not an issue at all. Smiling

0
No votes yet
Your rating: None

Pennsylvania Furry? Be sure to check out http://www.pa-furry.org/

Protocollie's picture
This user is a Staff Member
Location: Philadelphia, PA
"Con Chair. (That means you're not allowed to move me.)"
Posts: 1277
Votes Received:
4.5
490 votes received
Buddy List

Worked flawlessly, and my other request went through, too.

0
No votes yet
Your rating: None
rainbow's picture
Location: Pittsburgh, PA
"Take a whole pail of water just to cool me down!"
Posts: 151
Votes Received:
4.7
10 votes received
Buddy List

Say, I was wondering just what all you can do with someone signed up as a buddy. I guess it just makes it easier to find the user if you want to track them or pm them? On another forum I'm on, I get a notice every time a "buddy" makes a post, but this doesn't happen here.
Thanks!

0
No votes yet
Your rating: None

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.