Your message dated Thu, 21 Jun 2012 19:53:20 +1000
with message-id 
<cancwvspnunod+ytytbe1yyd_dyf22v3s3aw05ah8ryocwm0...@mail.gmail.com>
has caused the   report #678278,
regarding simpleid: refers to html/consent.js, but only html/openid-consent.js 
exists
to be marked as having been forwarded to the upstream software
author(s) Kelvin Mo <[email protected]>

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
678278: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=678278
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Hello,

I can confirm this is a bug.

A ticket has been created here:
https://sourceforge.net/apps/trac/simpleid/ticket/112

Kelvin

On 21 June 2012 05:27, Lionel Elie Mamane <[email protected]> wrote:
> On Wed, Jun 20, 2012 at 03:30:21PM +0000, Daniel Pocock wrote:
>
>> - impact of the bug (e.g. security risk?  completely non-functional?)
>
> I don't know; openid-consent.js seems to contain a security warning
> triggered in some conditions ("fraudulent webiste"), so possibly that
> warning will not come when it should; this would be a security bug.
>
> It does not make SimplID completely non-functional. It works.
>
>> - workaround attempted (renaming or correcting page.inc)?
>
> No.
>
>> - symptoms of the bug - did anything unusual happen that caused you to
>> notice this?
>
> No, but see above for my theory.
>
>> On 20/06/12 14:27, Lionel Elie Mamane wrote:
>> > Package: simpleid
>> > Version: 0.8.1-10
>> > Severity: normal
>> >
>> > In /usr/share/simpleid/www/page.inc:
>> >
>> >     $xtpl->assign('javascript', '<script src="' . get_base_path() . 
>> > 'html/consent.js" type="text/javascript"></script>');
>> >
>> > but:
>> >
>> > $ ls /usr/share/simpleid/www/html/consent.js
>> > ls: cannot access /usr/share/simpleid/www/html/consent.js: No such file or 
>> > directory
>> >
>> > However,
>> >
>> > $ ls /usr/share/simpleid/www/html/openid-consent.js
>> > /usr/share/simpleid/www/html/openid-consent.js
>> >
>> >
>> > Maybe *that* file was meant?
>> >


--- End Message ---

Reply via email to