View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
09634 | Feature requests | Survey taking | public | 2015-05-15 12:51 | 2015-05-15 12:57 |
Reporter | DenisChenu | Assigned To | DenisChenu | ||
Priority | normal | Severity | feature | ||
Status | closed | Resolution | suspended | ||
Fixed in Version | 2.05+ | ||||
Summary | 09634: A way to allow iframe survey with different domain | ||||
Description | In 2.06 : using this config: Allow iframe survey with different domain. PHPSESSID is set in POST or GET value according to PHP system. BUT :
| ||||
Additional Information | I have an idea to useTransparentSessionID true only for survey public part in a plugin. Then maybe nothing is needed.
config array is only accessible by real admin user, then it's not a major break issue . User choose to break some security rules, we can alert in manual. Another way is to update LS core to allow this settings and use more control on session. We already have CSRF, this give some more security, but needed more ? | ||||
Tags | No tags attached. | ||||
Bug heat | 2 | ||||
Story point estimate | |||||
Users affected % | |||||
Oups ... 'session' => array( Does the trick in 2.05 and 2.06. Admin still inaccessible BUT : different domain can be used and update config according to dmain is possible too. If needed : i update manual when i found some times (didn't explai the way to have 2 domains). |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2015-05-15 12:51 | DenisChenu | New Issue | |
2015-05-15 12:51 | DenisChenu | Additional Information Updated | |
2015-05-15 12:57 | DenisChenu | Note Added: 32209 | |
2015-05-15 12:57 | DenisChenu | Status | new => closed |
2015-05-15 12:57 | DenisChenu | Assigned To | => DenisChenu |
2015-05-15 12:57 | DenisChenu | Resolution | open => suspended |
2015-05-15 12:57 | DenisChenu | Fixed in Version | => 2.05+ |