Re: [Koha] SIP2 AF field sent even if patron password is invalid

2014-08-06 Thread Galen Charlton
Hi, On Tue, Aug 5, 2014 at 1:49 PM, Scott Kushner wrote: > Put me down as a big NO THANK YOU for requiring pin numbers at checkout, if > that's what we are talking about. It isn't, at least not quite. One of the things being proposed is that *if* the SIP2 device supplies a patron password/PIN

Re: [Koha] SIP2 AF field sent even if patron password is invalid

2014-08-06 Thread Scott Kushner
m: Koha [mailto:koha-boun...@lists.katipo.co.nz] On Behalf Of Katrin Fischer Sent: Saturday, August 02, 2014 8:32 AM To: koha@lists.katipo.co.nz Subject: Re: [Koha] SIP2 AF field sent even if patron password is invalid Hi, In my experience not all libraries require a password or PIN at the self ch

Re: [Koha] SIP2 AF field sent even if patron password is invalid

2014-08-02 Thread Katrin Fischer
Hi, In my experience not all libraries require a password or PIN at the self check station. One of the reasons can be that the self check used doesn't have a full keyboard but only a number pad and we can't limit passwords in Koha to be only numeric. So keeping the option to work without passwords

Re: [Koha] SIP2 AF field sent even if patron password is invalid

2014-08-01 Thread Galen Charlton
Hi, On Thu, Jul 31, 2014 at 9:21 AM, Colin Campbell wrote: > Many of the early sip devices considered the fact a user had wanded a > barcode, security enough. I recall machines which sent blank passwords > meaning 'I dont care about passwords and if they're valid'. The > implication of the standa

Re: [Koha] SIP2 AF field sent even if patron password is invalid

2014-08-01 Thread Colin Campbell
On Thu, Jul 31, 2014 at 07:25:49AM -0400, Kyle Hall wrote: > > As far as I can tell, the SIP2 spec does not intend a bad user password to > limit any data, it up to the client to determine what and what not to > display given a bad patron password. > Many of the early sip devices considered the f

Re: [Koha] SIP2 AF field sent even if patron password is invalid

2014-07-31 Thread Kyle Hall
I think the essential problem is SIP has two levels of authentication. The SIP server level, then the patron level. I think the SIP protocol intends for the SIP client to behave responsibly with the data it gets, but in reality SIP device manufacturers don't seem to try very hard. For instance, wh