[Bb-trac] [bbPress] #955: Installer does not automatically create 'secret' keys for cookies

bbPress bb-trac at lists.bbpress.org
Tue Sep 2 09:01:06 GMT 2008


#955: Installer does not automatically create 'secret' keys for cookies
----------------------------------+-----------------------------------------
 Reporter:  BjornW                |       Owner:                                  
     Type:  defect                |      Status:  new                             
 Priority:  normal                |   Milestone:                                  
Component:  Installation/Upgrade  |     Version:  1.0-alpha-1                     
 Severity:  major                 |    Keywords:  installer, cookies, empty values
----------------------------------+-----------------------------------------
 I downloaded the latest 1.0 alpha from the site. After starting the
 installer, I get step1 in which I fill in my database information and I
 continue. My bb-config.php cannot be written automatically (perhaps a
 check before might be a tad more userfriendly?) and I notice that the keys
 for the cookies have been left empty. Going back in the installer and
 checking the advanced options I notice that they are also empty here. I
 would expect them to be automatically generated using api.wordpress.com or
 any other mechanism. AFAIK empty values are not so great for security.

 I suggest generating a string during the installation of a new bbpress
 install.

-- 
Ticket URL: <http://trac.bbpress.org/ticket/955>
bbPress <http://bbpress.org/>
Innovative forum development


More information about the Bb-trac mailing list