Forum OpenACS Q&A: Re: Excellent New Site

Collapse
8: Re: Excellent New Site (response to 1)
Posted by Jeff Davis on
Simon, the testing forum numbering is fixed (it was a bug in the paginator code; I fixed on 4.6 as well).

Ben, one pretty negative aspect with the "reply by email" is that it is so easily spoofed since it is all public information (the object id and user id). Maybe it does not matter that it is so easy to masquerade as another user but I think it would not be too hard to fix. We could add a signature to the reply-to address which could just be the first part hashed together with a server secret so you would have a reply-to like "notifications-59600-4087-b4a45c20@openacs.org" which could then be checked to make sure the reply to is genuine.

Collapse
Posted by Simon at TCB on
Thanks Jeff, much appreciated!