Options

Bogus Site-wide Customization login prompt

micknewtonmicknewton Registered Users Posts: 269 Major grins
edited September 21, 2008 in SmugMug Support
Since yesterday, when ever I click the 'Site-wide Customization' link on my control panel I get sent to the login page, even though I'm already logged in.

This extra login prompt is totally unnecessary because you shouldn't even be able to see the control panel unless you're already logged in.

Comments

  • Options
    AllenAllen Registered Users Posts: 10,012 Major grins
    edited September 20, 2008
    micknewton wrote:
    Since yesterday, when ever I click the 'Site-wide Customization' link on my control panel I get sent to the login page, even though I'm already logged in.

    This extra login prompt is totally unnecessary because you shouldn't even be able to see the control panel unless you're already logged in.
    I got into mine ok, see if clearing cookies helps.
    Al - Just a volunteer here having fun
    My Website index | My Blog
  • Options
    rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited September 20, 2008
    Mick,

    Since you seem to have set your SmugMug account to keep you logged in even when you close your browser, it's not true that you have to know the password for the account to see the control panel. What about if you're not at your computer? Anyone else could open the browser, go to your SmugMug site, click on control panel and screw around with your customizations.

    That's why for sensitive account settings, like changing your email address or password you always had to login again if you hadn't authenificated yourself for this browser session. It seems as if this security precaution was expanded to include the customizations as well. If you haven't logged in yet since you opened the browser, you would have to authentificate yourself by entering your login. After having logged in once, you can go back to the customizations unless you close your browser and re-open it.

    I hope this explains things.

    Sebastian
    Sebastian
    SmugMug Support Hero
  • Options
    micknewtonmicknewton Registered Users Posts: 269 Major grins
    edited September 20, 2008
    Mick,

    Since you seem to have set your SmugMug account to keep you logged in even when you close your browser, it's not true that you have to know the password for the account to see the control panel. What about if you're not at your computer? Anyone else could open the browser, go to your SmugMug site, click on control panel and screw around with your customizations.

    That's why for sensitive account settings, like changing your email address or password you always had to login again if you hadn't authenificated yourself for this browser session. It seems as if this security precaution was expanded to include the customizations as well. If you haven't logged in yet since you opened the browser, you would have to authentificate yourself by entering your login. After having logged in once, you can go back to the customizations unless you close your browser and re-open it.

    I hope this explains things.

    Sebastian
    I used to be able to open my browser, go to my home page, click the control panel link, click the customize link, and it would show me my customize page.

    Now, when I click the customize link (now called "Site-wide Customization") I get sent to the login page. I don't know why, but it often takes a long time for the login page to load. That's the major reason that I choose the option to stay logged in when I close the browser.

    So, now I have to wait for the login page to load, log in, then click the link to take me to my customize page, then wait for the customize page to load.

    This is stupid because I'm already logged in as soon as I hit my home page. Yes, it only makes me login when I first open my browser, but it's annoying to have to go through all this when I'm already logged in. If I were worried about someone getting into my customize page and messing things up, then I would select the option to log out when I close my browser.
  • Options
    fdjcorpfdjcorp Registered Users Posts: 29 Big grins
    edited September 21, 2008
    I agree, I experience exactly the same issue
    This just started a couple of days ago from today OCT 21, 2008 Sunday.

    Freddie
  • Options
    AndyAndy Registered Users Posts: 50,016 Major grins
    edited September 21, 2008
    fdjcorp wrote:
    This just started a couple of days ago from today OCT 21, 2008 Sunday.

    Freddie
    Yes. We made the cobrand.mg page more secure now. Thanks for noticing thumb.gif
  • Options
    AndyAndy Registered Users Posts: 50,016 Major grins
    edited September 21, 2008
    micknewton wrote:
    This is stupid because I'm already logged in as soon as I hit my home page

    Sorry - we recently made cobrand.mg more secure. It's for everyone's benefit thumb.gif
  • Options
    rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited September 21, 2008
    micknewton wrote:
    I used to be able to open my browser, go to my home page, click the control panel link, click the customize link, and it would show me my customize page.
    [...|
    This is stupid because I'm already logged in as soon as I hit my home page. Yes, it only makes me login when I first open my browser, but it's annoying to have to go through all this when I'm already logged in. If I were worried about someone getting into my customize page and messing things up, then I would select the option to log out when I close my browser.
    Mick,

    It was only a simple example I used. We have added this security precaution to prevent your customizations from being changed by other people. Since you didn't have to authentificate yourself in the past with your login and password, it was theoretically possible that the request to change your customizations coming via a non-secured connection could have been intercepted by hackers. That would have enabled them to simply change your site customizations without having to know your login data. Now, this isn't possible anymore since they would have to get themselves authentificated first before being able to make any changes.

    I understand that this is another step that you need to take, but it's a security step that is necessary to ensure the safety of your site. Please understand that protecting the safety of your site is more important to us than this in comparison very small additional step.

    If you have any further questions, let us know.

    Sebastian
    Sebastian
    SmugMug Support Hero
  • Options
    micknewtonmicknewton Registered Users Posts: 269 Major grins
    edited September 21, 2008
    I dunno, it feels a bit like the patriot act to me. Are you sure we're not giving up our freedom for a bit of imagined security?

    No need to answer that. I'm just being facetious. Like the patriot act, I don't like it, but I guess I'll have to live with it. :D
  • Options
    AndyAndy Registered Users Posts: 50,016 Major grins
    edited September 21, 2008
    micknewton wrote:
    I dunno, it feels a bit like the patriot act to me. Are you sure we're not giving up our freedom for a bit of imagined security?

    No need to answer that. I'm just being facetious. Like the patriot act, I don't like it, but I guess I'll have to live with it. :D
    rolleyes1.gifrolleyes1.gif
Sign In or Register to comment.