X-Git-Url: http://git.harvie.cz/?a=blobdiff_plain;f=doc%2FTODO;h=0866ad2e0bd52ac18f44cd95cbdfe3f700a6c707;hb=38d469f590f00881f259a72b7ff4a7648b3022c6;hp=95ccf36ac55f8cca2f51948a718051ceebd0a51a;hpb=1ca26066fd412911ba5a08461c0c076d93b12932;p=mirrors%2FKyberia-bloodline.git diff --git a/doc/TODO b/doc/TODO index 95ccf36..0866ad2 100644 --- a/doc/TODO +++ b/doc/TODO @@ -1,17 +1,20 @@ -- User mail is not working - (seems to be fixed, but we still can't delete the mails...) - Anyway move whole mail handling out of nodes.php (?) +- When adding node, content is escaped twice(?) + +- Registration process -> Add welcome texts & move them to one file/node + Temporary requests node does not exists. + Nodes are created with bad vector + (during registration we should generate GnuPG keypair + to user_gpg_prv and user_gpg_pub fields in table users) (harvie) + +- Fix uploading user images -- Registration process is not working - (rewrite sending of reg. mails) (TEST) - (during registration we should generate GnuPG keypair to user_gpg_prv and user_gpg_pub fields in table users) +- User mail -> can't delete the mails... + Anyway move whole mail handling out of nodes.php (?) - SQL injections (many fixed, but some should be still there) - remove absolute paths from all source files (!) -- User images (icons) seems to be broken somehow - - remove hard-coded hostname from: ( registration mails ) ( scripts in "scripts" directory (system paths)) @@ -39,8 +42,7 @@ - Test & scale logarithmic threading -- some templates are fixed only in .tpl, not in sql database - => synchronize .tpl vs SQL templates (permanently) +- Remove templates from git (they should be only in sql) - Clean code => fix uninitialized variables @@ -50,5 +52,7 @@ - Switch completely to Base36 (Templates, Links, don't change $_GET[], queries should convert between base10 in db and base36 in kyberia automatically, etc...) - (IMHO we should use SHA1 or stronger algorithm instead of MD5 for storing passwords) - (We really need this... I've cracked Hromi's password in few seconds (even when it was relatively secure)) (I've implemented this partially. We can now login using various hash algorithms, it's backward compatible, but we still need to edit registration/password changing to use SHA1 when updating passwords in DB) + +- Rename all files&directories that should not be rewrited to PATH_INFO to start with "_" (and if they should be also ignored by git they should start with "-") + (Rename images to _images - and fix hardcoded stuff...)