[pmwiki-users] commenting to private pages

Hans design5 at softflow.co.uk
Tue Dec 19 17:55:42 CST 2006


Tuesday, December 19, 2006, 10:33:33 PM, Patrick wrote:

> FWIW, it looks like you're retracing the exact same steps that I 
> had gone through with developing ?action=insert back in October,
> except I was calling the new level 'insert' instead of 'post'.

> It may also be worth noting that I think ?action=insert could
> end up obsoleting much of this once I get it working.  (And the
> fact that I haven't gotten it working yet is probably a good
> indication of how difficult it is to get the security correct
> for this type of action.)  

> I recognize that people are impatient to get something working, 
> but it's also important that it be done right.

Sure. I don't know if I am impatient. I enjoy the challenge to see if
something can be done, within the current framework.
I am sorry I was not here to witness the discussion about
action=insert. I read  with interest
http://www.pmwiki.org/wiki/PmWiki/Comments-UseCases

I knew that the commentbox recipe could do quite a bit of it, and when
I found adddeleteline2 it sort of clicked to combine these as a
general form extension processor. I reckon Fox can handle all
of the Comments-UseCases, I just hope I got the security
considerations right. But of course a lot can be improved, and there
may be quite different and better ways to do it, and a new insert
action may make it obsolete, or opens the door for great improvements.

May I also point out that AddDeleteLine2 and Fox add the option to
have post deletion, and that both adding and deleting posts should
be considered regards security and handling issues.


Hans





More information about the pmwiki-users mailing list