Ever going to have HTTPS? - About xda-developers.com

I'd love to be able to login to xda developers forum using HTTPS so I'm not sending my password plaintext over the net. Is this likely to be possible soon?

@jez9999, you can keep up with the updates on HTTPS for XDA in this thread.

As @ИΘΘK¡€ said, please post updated in that thread.
If you check out the form we actually do pass login information via https.
Closing this thread, please continue in the other one.

Related

XDA Twitter - Automatic RSS Updates

Hello there, i have worked a system to follow forum posts on Twitter, here are the currently supported threats:
XDA Twitter for Front Page forum: xda_developers
XDA Twitter for Kaiser General forum: xda_kaiser
Each one is updated every hour getting the last RSS post.
The Twitter idea is from robboy who gave me the password to work the system. The original post can be found here.
If you have any idea, suggestion, improvement for the twitter just let me know!
- Also let me know if you want another threat to follow -
That's a really good idea! Maybe you could do this for the ROM development threads, so we know when a new or updated ROM comes out.
aha, so you're the reason we couldn't register that twitter username
Flar
Site admin

XDA Site constant advert SPAM

Can anyone ahead some light on the constant spam of adverts and pop-ups i get when visiting the xda site on my phone? I can't browse xda anymore with my phone as a pop-up appears every 10 seconds redirecting me to a damn download link as my device has a supposed virus. Not only do you get pop-ups and redirects, but the site starts downloading "mobilegenie.apk" without my permission. How is all this shi!t allowed? Someone explain please, it is really annoying me I am now forced to use adblock just to view a few forum pages.
PS: i know tapatalk exits, i use it more than anything....but the times i need to view xda in the browser, i simply can't....on ANY rom.
Thread Closed​
We are currently working on fixing this issue. Please use the existing thread to report, thanks
http://forum.xda-developers.com/showthread.php?t=1696660​

403 Forbidden error when accessing post created by me using URL

If i use the URL https://forum.xda-developers.com/galaxy-note-8/help/able-to-whitepages-people-search-note-8-t3817418 which is a thread I have created in any browser after I am logged in, I will get a 403 Forbidden error as seen in the screen shot. However, the URL works fine when I am logged out of the site in any browser and I can reach the thread while logged on either by going to the specific forum itself and finding the thread or visiting my own profile in any other thread I have a post in, clicking on the post itself after showing posts I have started. This problem has happened ever since I originally created that specific thread.
Just for reference, I can access this thread fine without problems using the URL:
https://forum.xda-developers.com/general/about-xda/403-forbidden-error-accessing-post-t3877220
Almighty1 said:
If i use the URL..........
Click to expand...
Click to collapse
I can confirm this and this is indeed a weird thing...
My Personal Findings on being able to see it or not:
~XDA Apps (The ClaRetoX Forum & XDA Labs) - Yes (No problems at all)
~Android Browser App (Firefox & Puffin) - NO (Returns 403 Error)
~PC Browser Software (Firefox & Internet Explorer) - NO (Returns 403 Error)
I even see that thread listed in your profile as well.
This is definitely something that the Administrators, @MikeChannon and @bitpushr, should be aware of for further investigation.
Good Luck!
~~~~~~~~~~~~~~~
UNLESS asked to do so, PLEASE don't PM me regarding support. Sent using The ClaRetoX Forum App on my Commodore VIC-20.
Ibuprophen said:
.............
This is definitely something that the Administrators, @MikeChannon and @bitpushr, should be aware of for further investigation.
Click to expand...
Click to collapse
Yup... one for @bitpushr
Mike
Ibuprophen said:
I can confirm this and this is indeed a weird thing...
My Personal Findings on being able to see it or not:
~XDA Apps (The ClaRetoX Forum & XDA Labs) - Yes (No problems at all)
~Android Browser App (Firefox & Puffin) - NO (Returns 403 Error)
~PC Browser Software (Firefox & Internet Explorer) - NO (Returns 403 Error)
I even see that thread listed in your profile as well.
This is definitely something that the Administrators, @MikeChannon and @bitpushr, should be aware of for further investigation.
Good Luck!
~~~~~~~~~~~~~~~
UNLESS asked to do so, PLEASE don't PM me regarding support. Sent using The ClaRetoX Forum App on my Commodore VIC-20.
Click to expand...
Click to collapse
Interesting, I kept thinking I was the only one who had the problem because I created the thread and didn't realized others have the error as well. The only way I can open the thread is either through my profile or directly to the forum where it was pasted. I know that thread was moved so not sure if that has anything to do with it.
Almighty1 said:
Interesting, I kept thinking I was the only one who...........
Click to expand...
Click to collapse
It looks like this was referred to bitpushr who's the Administrator for the Technical Side of the XDA Server and such.
It may take a little time for this to be looked into with other server issues he's currently working on.
~~~~~~~~~~~~~~~
UNLESS asked to do so, PLEASE don't PM me regarding support. Sent using The ClaRetoX Forum App on my Commodore VIC-20.
Ibuprophen said:
It looks like this was referred to bitpushr who's the Administrator for the Technical Side of the XDA Server and such.
It may take a little time for this to be looked into with other server issues he's currently working on.
~~~~~~~~~~~~~~~
UNLESS asked to do so, PLEASE don't PM me regarding support. Sent using The ClaRetoX Forum App on my Commodore VIC-20.
Click to expand...
Click to collapse
Yeah, I realized that, what I meant was thanks for confirming the problem as someone who is not the OP having the same issue(s).
Almighty1 said:
If i use the URL https://forum.xda-developers.com/galaxy-note-8/help/able-to-whitepages-people-search-note-8-t3817418 which is a thread I have created in any browser after I am logged in, I will get a 403 Forbidden error as seen in the screen shot. However, the URL works fine when I am logged out of the site in any browser and I can reach the thread while logged on either by going to the specific forum itself and finding the thread or visiting my own profile in any other thread I have a post in, clicking on the post itself after showing posts I have started. This problem has happened ever since I originally created that specific thread.
Just for reference, I can access this thread fine without problems using the URL:
https://forum.xda-developers.com/general/about-xda/403-forbidden-error-accessing-post-t3877220
Click to expand...
Click to collapse
MikeChannon said:
Yup... one for @bitpushr
Mike
Click to expand...
Click to collapse
This should be fixed now. Reference: https://forum.xda-developers.com/ge...ccess-to-page-2-threads-t3915767/post79211243
This error indicates that the server has determined that you are not allowed access to the thing you've requested, either on purpose or due to a misconfiguration . It's probably because the site owner has limited access to it and you don't have permission to view it. The vast majority of the time, there's not much you can do to fix things on your (*client) end. There are four common causes for 403 Forbidden error (server side) . Here they are listed from most likely to least likely:
An empty website directory
No index page
Incorrect settings in the .htaccess file
Permission / Ownership error
If authentication credentials were provided in the request, the server considers them insufficient to grant access. The client SHOULD NOT automatically repeat the request with the same credentials. The client MAY repeat the request with new or different credentials. However, a request might be forbidden for reasons unrelated to the credentials.

Not able to access private messages section

Hello folks,
I registered here some time ago to ask some questions about xposed module development.
I got the answers I needed, completed the module, released it and updated it a few times since then.
Now I received an email that someone contacted me here via private message to ask some questions about this module.
Well I'd like to answer but I really have trouble navigating to this page.
[...]
To read the original version, respond to, or delete this message, you must log in here:
https://forum.xda-developers.com/private.php
This is the message that was sent:
[...]
Click to expand...
Click to collapse
If I log in and navigate to the given link I get redirected to https://forum.xda-developers.com/register.php?from=permissions (I'm still logged in)
vBulletin Message
Our records show that you have already registered under the name of toni.xda. If you have lost your password, click here. If you would like to modify your profile, click here.
Click to expand...
Click to collapse
429 Rate Limited
Whoa there, hold your horses! We've detected a lot of requests coming from your IP and have rate limited you. Please check your configuration and try again.
Click to expand...
Click to collapse
Does this sound familiar to anyone?
I remember having problems using the correct subforums when I developed the module because I didn't have enough reputation/posts/whatever.
May this also be the cause for not being able to access the private messages section?
toni.xda said:
Hello folks,
I registered here some time ago to ask some questions about xposed module development..........
Click to expand...
Click to collapse
Try logging out, clean your browser cookies, restart your browser, go to any thread/area then log back in and try the same https://forum.xda-developers.com/private.php link again.
Make sure you don't have multiple profiles on XDA because the server may be seeing activity on multiple profiles from the same IP Address as well.
If this is some type of an ongoing account issue, you may need to contact @MikeChannon (an XDA Administrator) to help you out with some further investigation regarding your account.
This is about the best guidance I can provide you with myself...
Good Luck!
~~~~~~~~~~~~~~~
UNLESS asked to do so, PLEASE don't PM me regarding support. Sent using The ClaRetoX Forum App on my Enigma Machine {aenigma = Latin for "Riddle"}.
Ibuprophen said:
Try logging out, clean your browser cookies, restart your browser, go to any thread/area then log back in and try the same https://forum.xda-developers.com/private.php link again.
Make sure you don't have multiple profiles on XDA because the server may be seeing activity on multiple profiles from the same IP Address as well.
If this is some type of an ongoing account issue, you may need to contact @MikeChannon (an XDA Administrator) to help you out with some further investigation regarding your account.
This is about the best guidance I can provide you with myself...
Good Luck!
~~~~~~~~~~~~~~~
UNLESS asked to do so, PLEASE don't PM me regarding support. Sent using The ClaRetoX Forum App on my Enigma Machine {aenigma = Latin for "Riddle"}.
Click to expand...
Click to collapse
Thank you, the problem does not appear on my notebook, so I guess there really might have been some cache inconsitencies on the other machine.

Password Reset Spoofing

Hey,
Ive just used the pw reset feature today,
and heck,
I was shocked when I entered my email adress into the input form and it prompted a message that my password reset was send to my email.
A password reset request has been emailed to you. Please follow the instructions in that email.
Click to expand...
Click to collapse
The prompted message should NOT give any detail if the entered email is used in the db, or not!
That needs to be adressed imho asap!
Simply by:
If true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
If not true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
Ty
@MikeChannon @the_scotsman
Gentlemen, for your attention please.
GuestNoOne said:
Hey,
Ive just used the pw reset feature today,
and heck,
I was shocked when I entered my email adress into the input form and it prompted a message that my password reset was send to my email.
The prompted message should NOT give any detail if the entered email is used in the db, or not!
That needs to be adressed imho asap!
Simply by:
If true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
If not true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
Ty
Click to expand...
Click to collapse
Contact Us | XDA Developers
Founded in 2002, XDA is the world’s largest smartphone and electronics community. Looking for the latest tech news and reviews? Want to do more with your Android phone, Windows PC, iPhone, iPad, or MacBook? Look no further than XDA.
www.xda-developers.com
Requests to Moderators and Recommendations for XDA improvements
[All XDA Members] Requests to Moderators and Admins [All XDA Members] Feedback/Recommendations for XDA
forum.xda-developers.com
sd_shadow said:
Contact Us | XDA Developers
Founded in 2002, XDA is the world’s largest smartphone and electronics community. Looking for the latest tech news and reviews? Want to do more with your Android phone, Windows PC, iPhone, iPad, or MacBook? Look no further than XDA.
www.xda-developers.com
Requests to Moderators and Recommendations for XDA improvements
[All XDA Members] Requests to Moderators and Admins [All XDA Members] Feedback/Recommendations for XDA
forum.xda-developers.com
Click to expand...
Click to collapse
What a mess in here... Instead of deleting this thread the mod decided to delete the post I made, after checking your reply, in:
https://forum.xda-developers.com/t/...recommendations-for-xda-improvements.4300729/
... but hey, its actually not a recommendation, its a security flaw and therefor bug report. So maybe the mod was right to leave this thread. Still confused
GuestNoOne said:
Hey,
Ive just used the pw reset feature today,
and heck,
I was shocked when I entered my email adress into the input form and it prompted a message that my password reset was send to my email.
The prompted message should NOT give any detail if the entered email is used in the db, or not!
That needs to be adressed imho asap!
Simply by:
If true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
If not true:
If this email is associated with an account, the password reset request has been emailed to it. Please follow the instructions in that email.
Ty
Click to expand...
Click to collapse
This matter has been referred to those who can officially review and potentially change the way the process works.
Mike
I just fixed this by standardizing verbiage across both situations. Thank you for bringing it to our attention @GuestNoOne !
Lol. Mods thanking each other to gain more likes - while the one who brought it up doesnt get any.
That phenomen got a name and aint healthy...
GuestNoOne said:
Lol. Mods thanking each other to gain more likes - while the one who brought it up doesnt get any.
That phenomen got a name and aint healthy...
Click to expand...
Click to collapse
Do you really expect an answer? Certainly not from me.
GuestNoOne said:
Lol. Mods thanking each other to gain more likes
Click to expand...
Click to collapse
We don't care about likes anymore, this is no longer significant at this point, for moderators at least. We are not chasing them.
GuestNoOne said:
while the one who brought it up doesnt get any.
Click to expand...
Click to collapse
Fixed! You got likes now, thanks!
Yeah that happens, I've seen moderators (myself included) affected by this situation as well, don't worry, e.g. a moderator posts a smart question or an interesting issue and only the other mod who answered got likes! This is not specific to non-moderators, trust me.
GuestNoOne said:
That phenomen got a name and aint healthy...
Click to expand...
Click to collapse
I know for sure there is nothing malicious here. Trust me here too

Categories

Resources