X-Git-Url: http://git.harvie.cz/?a=blobdiff_plain;f=doc%2FTODO;h=41b464c7a0bc6c3a9e1cba6b86104ccdefc19b3b;hb=10daeb15c0681b8e142f8770646b3542b3dc88ec;hp=135cc79bd20ad2eaac24801a806f59700237b898;hpb=dcee763368a1e3f380d07320a5254d91a09304e6;p=mirrors%2FKyberia-bloodline.git diff --git a/doc/TODO b/doc/TODO index 135cc79..41b464c 100644 --- a/doc/TODO +++ b/doc/TODO @@ -1,8 +1,17 @@ +- User mail is not working + +- Registration process is not working + (IMHO we should use SHA1 or stronger algorithm instead of MD5 for storing passwords) + +- Cron scripts are not executed + (no automatic logouts, no K generation, ...) + - fix uploading of files + - fix ALL sql injections -- keep fixing XSS -- documentantion/instalation guide (see README) + - remove absolute paths from all source files (!) (over 50) + - remove hard-coded kyberia.sk from: ( ./inc/eventz/configure_email.inc ) ( ./inc/eventz/delete.inc ) @@ -11,10 +20,21 @@ ( ./nodes.php ) ( ./cron/rssparse.php ) ( ./scripts/contentregexp.php ) (obsolete?) + Fix https vs http problem (url) - Suspected security holes: ( cron/process-img.sh ) ( sms_payment.php => yes, sqli but is it really used? ) - ( inc/eventz/upload_data_node.php => Shell injections in .zip hanling, .jpg handling, + ( inc/eventz/upload_data_node.php => Shell injections in .zip handling, .jpg handling, "strange" filenames like .htacess (to allow listing of folder) +- Refactor directory structure + +- Deprecated PHP features + ( Deprecated: Assigning the return value of new by reference is deprecated in /srv/kyberia/wwwroot/nodes.php on line 163 Deprecated: Assigning the return value of new by reference is deprecated in /srv/kyberia/wwwroot/nodes.php on line 184 Deprecated: Assigning the return value of new by reference is deprecated in /srv/kyberia/wwwroot/nodes.php on line 196 Deprecated: Assigning the return value of new by reference is deprecated in /srv/kyberia/wwwroot/nodes.php on line 208 Deprecated: Assigning the return value of new by reference is deprecated in /srv/kyberia/wwwroot/nodes.php on line 220 Deprecated: Assigning the return value of new by reference is deprecated in /srv/kyberia/wwwroot/nodes.php on line 242 ) + +- keep fixing XSS + +- documentation/installation guide (see README) + +- Clean code => fix uninitialized variables