A Conversation for SSO and Digiboxes: Problems, Alternative Solutions and Suggestions.
Email-able Login Link
SEF Posted Oct 24, 2003
When you do show=1 like that, Rho, you make rather a lot of links for people using plain which might prevent them viewing the post (like the Askh2g2 problem).
Copy of Rho's post follows:
==========================
Digibox users can email themselves links. Why not get each digibox user to email themself a link that will log them in?
www.bbc.co.uk/cgi-perl/signon/mainscript.pl?service=h2g2&username=user&password=pass
is a link that will log in the person to h2g2 with the username 'user' and the password 'pass', taking them to the frontpage in their default skin (plain for almost all digibox users).
All each digibox user need do after migrating their account is email themself <a href="www.bbc.co.uk/cgi-perl/signon/mainscript.pl?service=h2g2&username=user&password=pass"> changing 'user' to their username and 'pass' to their password, then click that link every time they want to login! Unless they changed their password, this link would never stop working.
The only downside is that, as the username and password would be visible in plaintext in that email, they'd have to make sure that nobody was looking over their shoulder when they used the link.
Email-able Login Link
Rho Posted Oct 24, 2003
Hasn't that problem been fixed? I see only about 30 links on the right hand side using plain (<./>/dna/h2g2/plain/T329837?skip=217&show=1</.>. Askh2g2 in plain has about 500 links.
Email-able Login Link
SEF Posted Oct 24, 2003
I've just tried the link with a non-migrated account but on a PC with IE6. NB I added the http bit at the beginning of the URL. It recognised me and asked me to continue with the migration process. That might work for a digibox user too as there are no SCRIPT or NOSCRIPT statements in the body of the page around the FORM to stop it being shown.
Email-able Login Link
Star Fleet... Posted Oct 24, 2003
if i create the link and send it will it let them back online or do they need to do it themselves ?? plus does it matter if they have been upgraded
Star Fleet
Email-able Login Link
SEF Posted Oct 24, 2003
They need to use their own login username (not nickname) and password. They shouldn't be giving you this information. So they really ought to make the link in an email to themselves without telling anyone else their details. I don't expect the digibox version/upgrade should make any difference since there are no SSO screens if the account has already been migrated and what looks like a safe screen if the account has not been migrated yet.
Email-able Login Link
Rho Posted Oct 24, 2003
I've written in more detail about this solution here: A1914491.
Loup: If you'd like to add any or all of this information to A1910062, please do!
Rho
Email-able Login Link
SEF Posted Oct 24, 2003
Nice page, Rho, but I think you should explicitly state somewhere that the username is *not* (necessarily) the same as the nickname. This seems to cause some confusion among all users - particularly those used to being permanently logged in (which includes many digibox users). They may not have seen their username in years!
Email-able Login Link
Rho Posted Oct 24, 2003
> Nice page, Rho,
Thanks!
> I think you should explicitly state somewhere that the username is *not* (necessarily) the same as the nickname
Done!
Rho
Email-able Login Link
kow Posted Oct 24, 2003
From A1914491
>>takes non-migrated accounts to a digibox friendly SSO screen.<<
Hi Rho, thanks for this it is indeed much better. However the above statement is only true for digibox users who have had the new TeleWest software upgrade. Those that haven't got it yet (the majority) cannot get past step 2 or 3.
Email-able Login Link
Rho Posted Oct 24, 2003
Ah, thanks! I'll add a note to that effect. In that case, these digibox users could (as they are) ask another Researcher / an Italic to migrate their account for them, then use a link to log into the migrated account.
Rho
Email-able Login Link
Jab [Since 29th November 2002] Posted Oct 25, 2003
Can you show the TARGET part please?
ie.
h2g2
For digibox full page.
Email-able Login Link
Loup Dargent Posted Oct 25, 2003
>I've written in more detail about this solution here: A1914491.
Loup: If you'd like to add any or all of this information to A1910062, please do!<
Rho... I will sure do... but in a crafty way as i'm lazy by nature...
like [for example] summarising the process and pointing the digibox users to the entry for more details...
I haven't been able to be online as much as i thought yesterday [] and today might be the same [
] so i will be very thankful to the "cut and paste" facility of the PC tomorrow and Monday and for a while longer until all the necessary infos are listed... then, when the polishing process for the page starts i will change the wording then and there...
Sure great to already see some alternative solutions though...
I might not add the other names in the Researchers Credits box straight away as obviously the infos are the priority for the page right now... So all you wonderful people, if you don't see your name on the list _yet_, don't worry: you haven't been forgotten...
Mmmmm... What else?!... Oh yeah... I'm going to make use of the Guidepost a lot to work on the page offline [the Guidepost is unfortunately not working for digiboxes so i won't go into details of what it is at the moment but will provide a link later on for those who have access to a PC and don't know what it is... _that_ was a useless waste of space what i've just said...
But hey, i have to maintain my status of one of the Researchers with the longest postings...
]
Right a few more postings before getting some sleep... I will keep you up to date with whatever i'm doing regarding the page [though most of the work will be done tomorrow and Monday as i won't be working those nights ()]... I will come back to you for some clarifications on some points if needed... Oh and yep the difference between username and screen name is important to mention.. i will also include it in the bit about the naming convention but it won't hurt if this clarification is made a few times...
Talk soon everyone...
loup
Email-able Login Link
Rho Posted Oct 25, 2003
> Can you show the TARGET part please?
I didn't know that that was needed for digibox users; I'll add it straight away.
> I will sure do
Great!
Rho
Email-able Login Link
Jab [Since 29th November 2002] Posted Oct 26, 2003
Hi Rho,
Yep 'TARGET' is best otherwise the initial view is a narrow band within the e-mail view.
Digibox users may know about the box reseting itself due to limited memory, it still can happen even with the plain skin.
This also had the effect of logging us out, as if a hard reset to reboot the digibox by removing the power had been done.
There is currently a link at the top left of the screen 'Sign out' it's best a digibox user does NOT click it.
There has been a change, now a re-boot does not sign out, which is better. It's like SSO is a replacement for the old myBBC.
Looking at the idea of a e-mail being passed around, I though it only a matter of time before paswords became shared by accident. So checked to see what happened 'user=' and 'passsord=' are not included.
Great! They can be left blank ie user=&password=
Reading a few threads/e-mails, some people have reported "a blank screen" well by not including the user and pasword the form for them is forced to appear.
It is important that a service= still be named though.
This means an e-mail with the cgi-pearl link and the older link can be put in the same mail.
ie. http://bbc.co.uk/dna/h2g2/plain also if the user wishes they can go right to their own personal space by adding 'U' and their user number.
ie. /plain/u123456
Should a Sign Out be clicked, even using this 'cgi' link, named user/assword or not will not sign users back in (currently). It is required that pa reboot be performed, before the link works again.
Email-able Login Link
Jab [Since 29th November 2002] Posted Oct 26, 2003
Oh and clicking the "Im not " link is a not the best idea A prower-on reboot will be required to sign back in.
There is another advantan to not naming auser or password...
The link is generic, and useful for jumping multiple IDs without signing out, or 'I'm not'
I've just done it from this user to the one set-up as a test the other week.
Email-able Login Link
Salt~n~Shake Posted Oct 26, 2003
thank you everyone, i've got my name back.. I did the link just as you directed and i'm on my own name for the fist time since SSO day.. no more saucyalleycat or ballisticalleycat, i'm in heaven.. but what about the people who are sitting at home who can't get in to read this? can an e-mail not be written in the same manner and sent out by the aces to friends etc asking them to pass it on to others.. I would be happy to pass this information on but it would be easier for a somebody on comupter to kick start it... thanks again..
Sam
Key: Complain about this post
Email-able Login Link
- 1: Rho (Oct 24, 2003)
- 2: SEF (Oct 24, 2003)
- 3: Rho (Oct 24, 2003)
- 4: kow (Oct 24, 2003)
- 5: SEF (Oct 24, 2003)
- 6: SEF (Oct 24, 2003)
- 7: SEF (Oct 24, 2003)
- 8: Star Fleet... (Oct 24, 2003)
- 9: SEF (Oct 24, 2003)
- 10: Rho (Oct 24, 2003)
- 11: SEF (Oct 24, 2003)
- 12: Rho (Oct 24, 2003)
- 13: kow (Oct 24, 2003)
- 14: Rho (Oct 24, 2003)
- 15: Jab [Since 29th November 2002] (Oct 25, 2003)
- 16: Loup Dargent (Oct 25, 2003)
- 17: Rho (Oct 25, 2003)
- 18: Jab [Since 29th November 2002] (Oct 26, 2003)
- 19: Jab [Since 29th November 2002] (Oct 26, 2003)
- 20: Salt~n~Shake (Oct 26, 2003)
More Conversations for SSO and Digiboxes: Problems, Alternative Solutions and Suggestions.
Write an Entry
"The Hitchhiker's Guide to the Galaxy is a wholly remarkable book. It has been compiled and recompiled many times and under many different editorships. It contains contributions from countless numbers of travellers and researchers."