Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   Bug Report (https://forums.graalonline.com/forums/forumdisplay.php?f=193)
-   -   RC login with account/communityname (https://forums.graalonline.com/forums/showthread.php?t=134260708)

xXziroXx 10-03-2010 03:43 PM

RC login with account/communityname
 
Could it be made so you can use the external RC with your community name or email? The same thing works on the client, would only make sense to have it work for RC.

MrDumbledore 10-03-2010 05:26 PM

On a related note, do you need to add the community name or account to staff= to allow access?

xXziroXx 10-03-2010 05:31 PM

Quote:

Originally Posted by MrDumbledore (Post 1603846)
On a related note, do you need to add the community name or account to staff= to allow access?

Community name.

MrDumbledore 10-03-2010 05:32 PM

Quote:

Originally Posted by xXziroXx (Post 1603848)
Community name.

That should be changed to account. Community names are essentially changeable and it's a security flaw (even if a small one).

Sorry for jacking your thread btw

xXziroXx 10-03-2010 05:34 PM

Quote:

Originally Posted by MrDumbledore (Post 1603849)
That should be changed to account. Community names are essentially changeable and it's a security flaw (even if a small one).

That's been requested for years now. It's stupid that you have to add community name to serveroptions, but you set rights on the account name.

Rufus 10-03-2010 05:55 PM

Quote:

Originally Posted by MrDumbledore (Post 1603849)
That should be changed to account. Community names are essentially changeable and it's a security flaw (even if a small one).

How is it a security flaw?

MrDumbledore 10-03-2010 05:57 PM

Quote:

Originally Posted by Rufus (Post 1603860)
How is it a security flaw?

They are changeable so if you have "SuperMan" in your staff= and he gets a change, and then someone else gets a change to "SuperMan", they have RC.

Rufus 10-03-2010 06:04 PM

Quote:

Originally Posted by MrDumbledore (Post 1603861)
They are changeable so if you have "SuperMan" in your staff= and he gets a change, and then someone else gets a change to "SuperMan", they have RC.

These SuperMen are going to have the same IP/PCID?

MrDumbledore 10-03-2010 06:05 PM

Quote:

Originally Posted by Rufus (Post 1603865)
These SuperMen are going to have the same IP/PCID?

Rights are set via account, therefore the "fake" SuperMan would have *.*.*.* as his IP.

Rufus 10-03-2010 06:09 PM

Quote:

Originally Posted by MrDumbledore (Post 1603867)
Rights are set via account, therefore the "fake" SuperMan would have *.*.*.* as his IP.

Then he'd have to convince the staff team (that are apparently unaware that SuperMan1 had his community name renamed?) and do it before SuperMan1 notices. Lmao.. I couldn't see this happening in the real world (ever) but I see your point.

MrDumbledore 10-03-2010 06:11 PM

Quote:

Originally Posted by Rufus (Post 1603869)
Then he'd have to convince the staff team (that are apparently unaware that SuperMan1 had his community name renamed?) and do it before SuperMan1 notices. Lmao.. I couldn't see this happening in the real world (ever) but I see your point.

In general security holes shouldn't be left open due to a low probability of them being exploited, but yes, it is unlikely.

Deas_Voice 10-04-2010 11:01 AM

Quote:

Originally Posted by MrDumbledore (Post 1603861)
They are changeable so if you have "SuperMan" in your staff= and he gets a change, and then someone else gets a change to "SuperMan", they have RC.

that's what IP Range is for, to prevent such thing.

salesman 10-04-2010 05:06 PM

Quote:

Originally Posted by Deas_Voice (Post 1604060)
that's what IP Range is for, to prevent such thing.

Quote:

Originally Posted by MrDumbledore (Post 1603867)
Rights are set via account, therefore the "fake" SuperMan would have *.*.*.* as his IP.

:asleep:

Tigairius 10-04-2010 07:03 PM

Major issue with RC & communityname/account names:

/openrights communityname doesn't work. You have to add their communityname to server options as staff, but then to open their rights you have to do /openrights Graal######. It's a bit annoying to do.

MrDumbledore 10-04-2010 07:22 PM

Quote:

Originally Posted by Tigairius (Post 1604114)
Major issue with RC & communityname/account names:

/openrights communityname doesn't work. You have to add their communityname to server options as staff, but then to open their rights you have to do /openrights Graal######. It's a bit annoying to do.

Indeed. Also see this thread.


All times are GMT +2. The time now is 03:02 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.