A Conversation for SSO and Digiboxes: Problems, Alternative Solutions and Suggestions.

Email-able Login Link

Post 1

Rho

<./>T329837?skip=217&show=1</.>. smiley - smiley

Rho


Email-able Login Link

Post 2

SEF

When you do show=1 like that, Rho, you make rather a lot of links for people using plain which might prevent them viewing the post (like the Askh2g2 problem).

Copy of Rho's post follows:
==========================

Digibox users can email themselves links. Why not get each digibox user to email themself a link that will log them in? smiley - smiley

www.bbc.co.uk/cgi-perl/signon/mainscript.pl?service=h2g2&username=user&password=pass

is a link that will log in the person to h2g2 with the username 'user' and the password 'pass', taking them to the frontpage in their default skin (plain for almost all digibox users).

All each digibox user need do after migrating their account is email themself <a href="www.bbc.co.uk/cgi-perl/signon/mainscript.pl?service=h2g2&username=user&password=pass"> changing 'user' to their username and 'pass' to their password, then click that link every time they want to login! Unless they changed their password, this link would never stop working.

The only downside is that, as the username and password would be visible in plaintext in that email, they'd have to make sure that nobody was looking over their shoulder when they used the link.


Email-able Login Link

Post 3

Rho



Hasn't that problem been fixed? I see only about 30 links on the right hand side using plain (<./>/dna/h2g2/plain/T329837?skip=217&show=1</.&gtsmiley - winkeye. Askh2g2 in plain has about 500 links. smiley - erm


Email-able Login Link

Post 4

kow

smiley - cheers Rho, I'll give this a try, will it only work for accounts that have been migrated though?


Email-able Login Link

Post 5

SEF

That does indeed look different with the << and >> smiley - bigeyes


Email-able Login Link

Post 6

SEF

Askh2g2 forum threads may still be a problem though smiley - erm


Email-able Login Link

Post 7

SEF

I've just tried the link with a non-migrated account but on a PC with IE6. NB I added the http bit at the beginning of the URL. It recognised me and asked me to continue with the migration process. That might work for a digibox user too as there are no SCRIPT or NOSCRIPT statements in the body of the page around the FORM to stop it being shown.


Email-able Login Link

Post 8

Star Fleet...

smiley - cool if i create the link and send it will it let them back online or do they need to do it themselves ?? plus does it matter if they have been upgraded smiley - flustered

Star Fleet
smiley - dontpanic


Email-able Login Link

Post 9

SEF

They need to use their own login username (not nickname) and password. They shouldn't be giving you this information. So they really ought to make the link in an email to themselves without telling anyone else their details. I don't expect the digibox version/upgrade should make any difference since there are no SSO screens if the account has already been migrated and what looks like a safe screen if the account has not been migrated yet.


Email-able Login Link

Post 10

Rho

I've written in more detail about this solution here: A1914491.

Loup: If you'd like to add any or all of this information to A1910062, please do! smiley - smiley

Rho


Email-able Login Link

Post 11

SEF

Nice page, Rho, smiley - biggrin but I think you should explicitly state somewhere that the username is *not* (necessarily) the same as the nickname. This seems to cause some confusion among all users - particularly those used to being permanently logged in (which includes many digibox users). They may not have seen their username in years!


Email-able Login Link

Post 12

Rho

> Nice page, Rho,

Thanks! smiley - biggrin


> I think you should explicitly state somewhere that the username is *not* (necessarily) the same as the nickname

smiley - runsmiley - space Done!



Rho


Email-able Login Link

Post 13

kow

From A1914491
>>takes non-migrated accounts to a digibox friendly SSO screen.<<

Hi Rho, thanks for this it is indeed much better. However the above statement is only true for digibox users who have had the new TeleWest software upgrade. Those that haven't got it yet (the majority) cannot get past step 2 or 3.smiley - smiley


Email-able Login Link

Post 14

Rho

Ah, thanks! I'll add a note to that effect. In that case, these digibox users could (as they are) ask another Researcher / an Italic to migrate their account for them, then use a link to log into the migrated account. smiley - smiley

Rho


Email-able Login Link

Post 15

Jab [Since 29th November 2002]

Can you show the TARGET part please?

ie.

h2g2

For digibox full page.


Email-able Login Link

Post 16

Loup Dargent

>I've written in more detail about this solution here: A1914491.

Loup: If you'd like to add any or all of this information to A1910062, please do!<

Rho... I will sure do...smiley - cool but in a crafty way as i'm lazy by nature...smiley - whistle like [for example] summarising the process and pointing the digibox users to the entry for more details...smiley - biggrin

I haven't been able to be online as much as i thought yesterday [smiley - cry] and today might be the same [smiley - steam] so i will be very thankful to the "cut and paste" facility of the PC tomorrow and Monday and for a while longer until all the necessary infos are listed... then, when the polishing process for the page starts i will change the wording then and there...smiley - biggrin

Sure great to already see some alternative solutions though...smiley - disco


I might not add the other names in the Researchers Credits box straight away as obviously the infos are the priority for the page right now... So all you wonderful people, if you don't see your name on the list _yet_, don't worry: you haven't been forgotten...smiley - smiley

Mmmmm... What else?!... Oh yeah... I'm going to make use of the Guidepost a lot to work on the page offline [the Guidepost is unfortunately not working for digiboxes so i won't go into details of what it is at the moment but will provide a link later on for those who have access to a PC and don't know what it is...
smiley - ok _that_ was a useless waste of space what i've just said...smiley - yikes But hey, i have to maintain my status of one of the Researchers with the longest postings...smiley - winkeyesmiley - silly]

Right a few more postings before getting some sleep... I will keep you up to date with whatever i'm doing regarding the page [though most of the work will be done tomorrow and Monday as i won't be working those nights (smiley - cool)]... I will come back to you for some clarifications on some points if needed... Oh and yep the difference between username and screen name is important to mention.. i will also include it in the bit about the naming convention but it won't hurt if this clarification is made a few times...smiley - smiley

Talk soon everyone...smiley - surfer

loupsmiley - fullmoon



Email-able Login Link

Post 17

Rho

> Can you show the TARGET part please?

I didn't know that that was needed for digibox users; I'll add it straight away. smiley - smiley


> I will sure do

Great! smiley - biggrin


Rho


Email-able Login Link

Post 18

Jab [Since 29th November 2002]

Hi Rho,

Yep 'TARGET' is best otherwise the initial view is a narrow band within the e-mail view.

Digibox users may know about the box reseting itself due to limited memory, it still can happen even with the plain skin.

This also had the effect of logging us out, as if a hard reset to reboot the digibox by removing the power had been done.

There is currently a link at the top left of the screen 'Sign out' it's best a digibox user does NOT click it.

There has been a change, now a re-boot does not sign out, which is better. It's like SSO is a replacement for the old myBBC.

Looking at the idea of a e-mail being passed around, I though it only a matter of time before paswords became shared by accident. So checked to see what happened 'user=' and 'passsord=' are not included.

Great! They can be left blank ie user=&password=

Reading a few threads/e-mails, some people have reported "a blank screen" well by not including the user and pasword the form for them is forced to appear.

It is important that a service= still be named though.

This means an e-mail with the cgi-pearl link and the older link can be put in the same mail.

ie. http://bbc.co.uk/dna/h2g2/plain also if the user wishes they can go right to their own personal space by adding 'U' and their user number.

ie. /plain/u123456

Should a Sign Out be clicked, even using this 'cgi' link, named user/assword or not will not sign users back in (currently). It is required that pa reboot be performed, before the link works again.


Email-able Login Link

Post 19

Jab [Since 29th November 2002]

Oh and clicking the "Im not " link is a not the best idea smiley - laugh A prower-on reboot will be required to sign back in.

There is another advantan to not naming auser or password...

The link is generic, and useful for jumping multiple IDs without signing out, or 'I'm not' smiley - erm

I've just done it from this user to the one set-up as a test the other week.


Email-able Login Link

Post 20

Salt~n~Shake

thank you everyone, i've got my name back.. I did the link just as you directed and i'm on my own name for the fist time since SSO day.. no more saucyalleycat or ballisticalleycat, i'm in heaven.. but what about the people who are sitting at home who can't get in to read this? can an e-mail not be written in the same manner and sent out by the aces to friends etc asking them to pass it on to others.. I would be happy to pass this information on but it would be easier for a somebody on comupter to kick start it... thanks again..

smiley - love Sam


Key: Complain about this post