View Full Version : [fixed] lostpw problem
tamarian
Mon 26th Nov '01, 3:30pm
Originally posted by Joshua Clinard
It's been a while since any developers have participated in this thread.
Too busy fixing it, I hope :)
ToraTora!
Mon 26th Nov '01, 3:36pm
Originally posted by tamarian
I think we're mixing bugs here :)
The activation code for new registrants is one problem (thread title), the other problems discussed may not be related and might actually be another bug?
I've only had the activation problem (fixed by commenting out the deletion line).
The various behaviours exhibited here may be due to different registration/email/passowrd options chosen.
actually no. It still draws on similar data to present to the user.
Activiation, does not activate a user. Vaidation, does not work, nor does the email a password. All work on the basis of registration, and member.php
Any suggestions on how to fix any of the above problems? I would be happy just to get the email password working again, like it did before i upgraded.
ToraTora!
Mon 26th Nov '01, 8:53pm
well, here is a update to my problem.
I did a "forgot my password" and of course, i should of known better, but i really did believe, for a fleeting moment, that all would be ok.
Well, i hit the link in my email, and sure enough, there is the chance to hit the profile link, and change my password, which is good news, however, once i tried it again, it erased my password from the prior attempt, and than give me the no permission screen, after i clicked on the link in my email.
Now, is there a time limit, or a number of times, that in one day a password can be sent out? This is the only thing i can think of that would cause a problem like this.
I do know, there are 24 hours for the link to be valid, however, there should be really no limit, or at least a optional limit to set for a amount of times a user can check on his password if he/she looses it, if that is indeed the case as I described above.
John
Tue 27th Nov '01, 9:11am
Toratora - your password bug was an issue in early 2.2.1 global.php. Please make sure that you are running the latest version of this file, and it will not be an issue.
Update for the activation codes bug coming in a moment...
John
Axel Foley
Tue 27th Nov '01, 1:39pm
Originally posted by John
Toratora - your password bug was an issue in early 2.2.1 global.php. Please make sure that you are running the latest version of this file, and it will not be an issue.
Update for the activation codes bug coming in a moment...
John
John, I've opened a ticket for the FORGOTTEN PW problem, but it hasn't been solved yet. I have the same problem as Tora Tora, I'm pasting you the contents to a mail I sent to the support at vB (specifically to eva2000):
=== MAIL QUOTE =====
Right now I made the following steps:
1) I logged out from the forum to delete the cookies
2) On the login page, I clicked on the FORGOTTEN PASSWORD link
3) A mail has been sent to me (you can find the generated mail attached)
4) I clicked on the link provided in the mail
5) I have been redirected to the LOGIN page
6) If I press the LOGIN button it tells me WRONG PASSWORD
7) If I enter my OLD password it works, and vB tells me: "Your password has now been reset and emailed to you. Please check your email to find your new password. To change your password, please use this form.".
8) The email arrived me correctly (have attached it to this one)
It resets my password ONLY after I have clicked on that link in the mail AND after I've logged in with my old password. Obviously, if I really forgot my password I couldn't login so I couldn't reset my password. ;)
So the problem appears to be that after clicking that URL the forum wants you to LOGIN, but in that phase the user DOESN'T KNOW his password anymore (he forgot it). It shouldn't ask you to login, but it should reset the pw immediately, I suppose. ;)
The actual version of vB is 2.2.1 (files dated 26/11)
PHP: 4.0.5
Apache: 1.3.20
MySql: 3.23.32
The email templates have all been REVERTED even though they were not modified.
=== MAIL QUOTE =====
Yesterday I redownloaded vB 2.2.1 and today re-upgraded (2.2.0) for the second time, I didn't know that you changed the scripts without changing the version number, I was quite confused about the thing. One last thing, I've also noticed that you made a NEW showgroups.php that wasn't present in yesterday's zip. I copied that manually. Should I be warned of any other changes?
I hope I can finally fix this forgotten pw problem, and I hope I won't have to upgrade to 2.2.1 for the third time. ;)
Thanks for the help.
...Axel
Axel Foley
Tue 27th Nov '01, 10:39pm
Freddie...
The RESET PASSWORD problem I and others have isn't solved with the changes John posted. I applied them, and didn't solve that issue.
Can you tell us more about this problem?
Thanks...
tubedogg
Tue 27th Nov '01, 11:09pm
The reset password problem is controlled by global.php and member.php, it does not have anything to do with register.php. I am going to split the posts off from here so we can keep the two issues straight.
linuxman25
Wed 28th Nov '01, 12:04am
so where is the latest global.php?
tubedogg
Wed 28th Nov '01, 12:08am
It is available in the member's area. The file was last changed before 2.2.1 was declared final.
ToraTora!
Wed 28th Nov '01, 12:09am
well, i upgraded, and there is no changes in my global.php file as far as 'hacks' or anything along those lines, and I am still having these problems...
if it is possible, a code snippet of the global fixes, and member.php fixes would be appreciated, either via email, or what have you, because from what i have read from other people that have upgraded to the latest VB, these problems remain.
ToraTora!
Wed 28th Nov '01, 12:10am
ok, so we have the global, now, what are the possiblities of getting the changes for the member.php file, or is there really no changes to worry about?
linuxman25
Wed 28th Nov '01, 12:13am
is there a seperate global.php file? i just redownloaded the entire 2.2.1 file and uploaded global.php in 3 places......still same prob.......
ToraTora!
Wed 28th Nov '01, 12:15am
thats what i was just going to ask as well...i must be missing something in the members area, because i only see downloads to the versions of vb....there was a time i seen all of the users site links, and things along that line..but i havent seen that for awhile, something i am doing wrong im sure...
linuxman25
Wed 28th Nov '01, 12:17am
i just redownloaded all files in the current 2.2.1 zip and uploaded them all.......still same prob.....
ToraTora!
Wed 28th Nov '01, 12:20am
Originally posted by linuxman25
i just redownloaded all files in the current 2.2.1 zip and uploaded them all.......still same prob.....
well, than im not certainly going to screw with it.
I sat for close to three days getting mine back up and running from the last upgrade, and i am not about to do it again, if the same problems exist in the newest version, or the one before it.
wished to hell i would of stuck with 2.03...there was nothing wrong with it at all, other than a upgrade to the 'must have' encryption. :(
linuxman25
Wed 28th Nov '01, 12:22am
exactly correct.......
sad to see all these bugs everywhere......
ToraTora!
Wed 28th Nov '01, 12:25am
Originally posted by linuxman25
exactly correct.......
sad to see all these bugs everywhere......
I should of known better....i tell myself everytime, to never fix anything that isnt broke, and so far, with VB, i have never had that problem, because it never is a crap shoot of quality with these guys, so, I took the plunge, and am now knee deep in ****, with a site 3/4 functional.
linuxman25
Wed 28th Nov '01, 12:26am
I do the same thing......
things were fine and then I went and listened to people...biggest mistake one can ever make.
tubedogg
Wed 28th Nov '01, 12:27am
I count 2 major bugs and 6 minor bugs, all but 3 of which have been fixed...That hardly qualifies as 'all these bugs everywhere'. You all seem to expect bugless software that will function perfectly on hundreds of combinations of OSes, webservers and PHP/MySQL versions on the first try. It isn't going to happen, there are always going to be bugs, and acting like this is the first software to ever spring a bug after release isn't going to help anything.
Anyway, all the files in the member's area are the latest files available. No changes have been made to any of the files in CVS in regards to this problem as it only became clear tonight that this was still a problem. John or one of the other developers will post a fix if they can when it is fixed.
linuxman25
Wed 28th Nov '01, 12:32am
you must have missed the show called "eight is enough" there Tube.
Look at it this way, if Microsoft released an upgrade that caused the start button to disappear and that was the only bug there was, they would catch lots of hell over it.....same difference here..........
ToraTora!
Wed 28th Nov '01, 12:35am
Originally posted by tubedogg
I count 2 major bugs and 6 minor bugs, all but 3 of which have been fixed...That hardly qualifies as 'all these bugs everywhere'.
Anyway, all the files in the member's area are the latest files available. No changes have been made to any of the files in CVS in regards to this problem as it only became clear tonight that this was still a problem. John or one of the other developers will post a fix if they can when it is fixed.
Tube, he is just voicing a concern is all. I realize there isnt that many bugs, but the ones that do exist are a major pain in the ass for us. I can live without all of the other bs that was added to the newest version, i really can, because in essence, those functions, are not what make the board functional to begin with. (whos online in thread blah, staff, rate thread in new reply...etc..)
You have to admit, things seem a little bit rushed this time out, as compared to the other times, and that is directly attributed to a lynch mob demanding encryption be added before 3.0.
I still have nothing but respect for vb, and would never say anything along the lines of "i will go buy something else than..blah blah blah" however, you must be a little bit more understanding of some of the problems we are having. It took a hell of alot of convincing to my business partner, that VB was what should, and will be run on our site, while he was convinced to go another route, with another brand, so.... I am catching a little hell for this to, and in short, some of these last few bugs, whether you will admit it or not, were caused by rushing this encryption out the door to please the masses.
I personally could of waited another year for 3.0, if all of the newest addons, and security were done rite, and done with the usual testing these guys do before releasing a product, but this last time around, i can say might be the last time for myself, or a few others, if the cutomer impatience dictates the usual high quality product that Jellsoft puts out.
tubedogg
Wed 28th Nov '01, 12:36am
If Microsoft (or us for that matter) released software that only had one bug I think they would deserve some kudos. Software development is not easy and debugging is even harder.
ToraTora!
Wed 28th Nov '01, 12:42am
Originally posted by tubedogg
If Microsoft (or us for that matter) released software that only had one bug I think they would deserve some kudos. Software development is not easy and debugging is even harder.
I think those points are realized, and completely understood by most here Tube. The problem is, this time around, VB kicked something out the door before adequately giving it the once over, because there was so much demand for this fricken encryption. All a person needs to do, is go back to that monstorousity of a thread, in which everybody was screaming bloody murder for encryption by 3.0 to figure that out.
linuxman25
Wed 28th Nov '01, 12:44am
Originally posted by tubedogg
If Microsoft (or us for that matter) released software that only had one bug I think they would deserve some kudos. Software development is not easy and debugging is even harder.
Never said it was easy Tube, never did.......
but, this is a php/sql script, not an entire O.S.
One thing I have found that is odd is that I tested 2.2.1 on a 2000 machine running php and and mysql and it actually worked fine. However, I know many linux boxes that have this issue that we're referring to.
tubedogg
Wed 28th Nov '01, 12:54am
I can honestly say that the release timing of 2.2.0 had nothing to do with the cry for encryption. I mean look at the date of that thread - 7 months ago, before the release of even 2.0.1. Encrypted passwords was only something that resurfaced in the last couple months internally. We did everything we normally do for a release - it was tested internally as usual, it was tested on external mod/dev sites...it's not like this was rushed out the door as you imply.
ToraTora!
Wed 28th Nov '01, 7:40am
Originally posted by tubedogg
I can honestly say that the release timing of 2.2.0 had nothing to do with the cry for encryption. I mean look at the date of that thread - 7 months ago, before the release of even 2.0.1. Encrypted passwords was only something that resurfaced in the last couple months internally. We did everything we normally do for a release - it was tested internally as usual, it was tested on external mod/dev sites...it's not like this was rushed out the door as you imply.
Has there been any developments in this problem, or solutions that we can look forward to soon? I mean...maybe Im writing this premature...
By what you wrote above, and just the way i am understanding what you wrote above...this was not a rush job at all....so, answer this for me. Could it not of waited until a full blown release of 3.0, rather than be a upgrade that has caused this much trouble?
If it was tested from one end to another, as you seem to imply, that is in basic essence, telling us that they knew about the bugs, and released it anyways, or, they tested it, but just not enough of it to realize there were some problems with certain situations such as the vaidations, and lost user passwords, and of course the session problem that has been brought to attention in another thread. Either way...it just doesnt make sense to me, to miss something like this with adequate testing...
Why would all of these major problems exist, if indeed this was not a rush to send something out the door, when in the past, we really havent had a real major problem with functions that completely hampered the performance or functionality of the board itself?
Of course, I am not talking about the security hole in 2.0 either.
2.03 was just fine, and i think most would of been just happy waiting a little bit longer to upgrade to 3.0 and than adding upgrades to 3.0 as needed, rather than take a perfectly working board like we had with 2.03, than have to upgrade two times to no avail, and have no option to revert back to what actually worked.
That is the problem tube, and I hate to break it in such a way to completely make you unhappy with what i have posted, but it is pissing a major portion of vb owners off that we have nothing rite now to either go back to, or actually upgrade to.
Its called, caught between a rock and a hard place.
Im sure the problem will be solved here shortly, but its in the meantime that is really causing the problems.
Axel Foley
Wed 28th Nov '01, 10:16am
ToraTora and Linuxman, here it is:
global.php (in forum dir, not the one in admin), line 323:
Original line:
if ($action!="register" and $action!="signup" and $action!="activate" and $action!="login" and $action!="logout" and $action!="lostpw" and $action!="emailpassword" and $action!="addmember" and $action!="coppaform" and $a!="act" and $a!="ver" and $action!="resetpassword") {
Modified line:
if ($action!="register" and $action!="signup" and $action!="activate" and $action!="login" and $action!="logout" and $action!="lostpw" and $action!="emailpassword" and $action!="addmember" and $action!="coppaform" and $a!="act" and $a!="ver" and $action!="resetpassword" and $a!="pwd") {
Many thanks to Pogo for the hint...;)
...Axel
linuxman25
Wed 28th Nov '01, 10:17am
gonna try now man!
linuxman25
Wed 28th Nov '01, 10:21am
Kewl.....that worked.....about time someone finally saw this problem!!! thanx very much!
John
Wed 28th Nov '01, 12:32pm
Attached is the global.php with the fix for this problem. Please download the attachment, and upload it to your board.
John
eva2000
Wed 28th Nov '01, 12:37pm
great :)
Steve_S
Wed 28th Nov '01, 1:42pm
Thanks.
Which directory does the global.php which John just posted on the previous page of this thread go in?
domain/forums or
domain/forums/admin
?
linuxman25
Wed 28th Nov '01, 1:43pm
not admin dir
Joshua Clinard
Wed 28th Nov '01, 5:01pm
Tubedogg, I count three files that have been updated since the zip file was declared final. These are register.php, global.php, and showgroups.php. It seems that even with the fixes, my board is still having some problems, and we just switched from an ezboard with a membership of more than 300, and have all these members trying to sign up, and more than a few are having problems...So this is not some trivail issue. Don't get me wrong, I love vB, but I ask that the developers keep looking into these problems.
Thanks.
Steve_S
Wed 28th Nov '01, 5:49pm
<wew> :)
The global.php which John posted on the previous page of this thread appears to have fixed the lost PW issue on my 2.2.1 never hacked version. Thanks.
Does anyone need another issue/bug confirmed or denied with 2.2.1 ? If so, please post and I will test.
tubedogg
Wed 28th Nov '01, 6:08pm
Originally posted by Joshua Clinard
Tubedogg, I count three files that have been updated since the zip file was declared final. These are register.php, global.php, and showgroups.php. It seems that even with the fixes, my board is still having some problems, and we just switched from an ezboard with a membership of more than 300, and have all these members trying to sign up, and more than a few are having problems...So this is not some trivail issue. Don't get me wrong, I love vB, but I ask that the developers keep looking into these problems.
Thanks. I never said there were no files changed, I said the global.php available in the member's area was the latest available at that time. I am not trivializing, I am putting it in perspective.
sifuhall
Wed 28th Nov '01, 7:07pm
I am not trivializing, I am putting it in perspective.
Heh, :)
Your perspective may be very different from ours!
DeeperImage
Sun 2nd Dec '01, 12:35pm
I have uploaded the global.php that Jon posted and still no fix, I noticed something in the email but i dont know if this would make any diff, I tried it both ways and no fix still.
EMAIL SENT TO ME
From: "DeeperImage.com - Forums Mailer" <webmaster@deeperimage.com>
To: jose@deeperimage.com
Subject: Your login details for DeeperImage.com - Forums All headers
Hello,
You have requested to reset your password on DeeperImage.com - Forums forums because you have forgotten your password. If you did not request this, please ignore it. It will expire and become useless in 24 hours time.
To reset your password, please visit the following page:
http://www.deeperimage.com/forums/member.php?a=pwd&u=&i=
I noticed the = sign at the end of this link does not highlight when i click it, then i copied the whole link and pasted into browser and still did not work, not sure if it makes any diff but i thought i would point it out.
When you visit that page, your password will be reset, and the new password will be emailed to you.
Your username is: Neo
To edit your profile, go to this page:
http://www.deeperimage.com/forums/member.php?action=editprofile
Yours,
DeeperImage.com - Forums team
tubedogg
Sun 2nd Dec '01, 10:56pm
In your case you are missing the userid and activationid for some reason...have you edited your email_lostpw template?
DeeperImage
Sun 2nd Dec '01, 11:13pm
Originally posted by tubedogg
In your case you are missing the userid and activationid for some reason...have you edited your email_lostpw template? Its fixed now, I am not sure what happened but i had not touched the email_lostpw. I just reinstalled it and now seems to be working good..Thanks to you :)..Now i just have to let my hair grow back out since i pulled about 80% of it in the last two days...:eek:
MarkB
Tue 11th Dec '01, 9:15pm
Ditto on this - uploaded the fresh global.php, and I get the same error as above. :(
freehtml
Thu 13th Dec '01, 11:24am
Originally posted by DeeperImage
I have uploaded the global.php that Jon posted and still no fix, I noticed something in the email but i dont know if this would make any diff, I tried it both ways and no fix still.
I am also getting the same error . Here is the email I that send to me when I request my password :
Hi, Emperor Chin,
Here are your login details for the bulletin board at http://forums.sanguo-online.com// .
Username = Emperor Chin
Password =
Don't forget that they are case sensitive!
To edit your profile, go to this page:
http://forums.sanguo-online.com//member.php?action=editprofile
[FAQ]
Please visit our FAQ Section for answers to commonly asked questions
http://www.sanguo-online.com/vbb//misc.php?s=&action=faq
Chin
Webmaster, Sanguo ONline.com
http://www.sanguo-online.com
Notice that the password field is blank ..
I am using version 2.21 and had also downloaded the latest "global.php" and still the same problem.
Here is my "email_lostpw" template :
Hi, $username,
Here are your login details for the bulletin board at $bburl.
Username = $username
Password = $password
Don't forget that they are case sensitive!
To edit your profile, go to this page:
$bburl/member.php?action=editprofile
[FAQ]
Please visit our FAQ Section for answers to commonly asked questions
http://www.sanguo-online.com/vbb//misc.php?s=&action=faq
Chin
Webmaster, Sanguo ONline.com
http://www.sanguo-online.com
Steve Machol
Thu 13th Dec '01, 12:24pm
You need to revert your email_lostpw and email_validated templates as per John's announcement:
http://www.vbulletin.com/forum/showthread.php?s=&threadid=33426
MarkB
Thu 20th Dec '01, 6:40pm
I'm still having problems - this is the email I got:
Hello,
You have requested to reset your password on UltimateMetal.com forums because you have forgotten your password. If you did not request this, please ignore it. It will expire and become useless in 24 hours time.
To reset your password, please visit the following page:
http://www.ultimatemetal.com/forum/member.php?a=pwd&u=1&i=3257048
When you visit that page, your password will be reset, and the new password will be emailed to you.
Your username is: Mark
To edit your profile, go to this page:
http://www.ultimatemetal.com/forum/member.php?action=editprofile
Yours,
UltimateMetal.com team
When visiting the link, it says it's not valid. Could it be automatically expiring instead of waiting the usual 24 hours??
Help :(
carpenter
Thu 20th Dec '01, 10:14pm
I downloaded the new global.php that John posted in this thread and it fixed the problem for me.:)
MarkB
Thu 20th Dec '01, 10:38pm
I did too, and it's still not working... :( I even made sure there were no hacks in it...
Dolamite
Thu 27th Dec '01, 12:21am
ok.... so i'm one of the people who uploaded johns file and it still dosnt work.....
new reg. users, get invalid password ....
so.... are you guys still working on this?
i'm glad i bought a lifetime membership to vb.... cuz i might need it (hint hint ;))
TommyBALL
Thu 27th Dec '01, 5:02am
I would suggest that those who still have trouble with this, submit a "trouble ticket" for som "prime support" :)
http://vbulletin.com/members/support.php
Regards
- Tommy
Dolamite
Tue 15th Jan '02, 10:39pm
think maybe ill just wait for 2.2.2 ......
:rolleyes:
vBulletin® v3.7.3, Copyright ©2000-2008, Jelsoft Enterprises Ltd.