4 ms·
Re: authentication. There are three paths to authentication presently. 1) Anonymous - Anonymous is a subject in the system with explicit permissions. When no
by KrisJordan 16y ago
Re: authentication.
There are three paths to authentication presently.
1) Anonymous - Anonymous is a subject in the system with explicit permissions. When no authentication is presented the system assumes you are the anonymous subject. This is the common case because most website content, for the types of websites we've seen on HiFi, are made up of entirely publicly readable content.
2) Cookie Based - We use your typical web app SHA1 hash with generated salt. Not the greatest form of authentication, susceptible to replay, but preferable to HTTP Basic.
3) HTTP Basic Based - Want to get rid of this sooner than later. Need to invest in digest but it has its problems. This is not used in the app but is useful for server-server API consumption, cURL scripts, etc.
As Joel mentioned, the backend is largely XHR driven. Results are rendered primarily with an evolution of Resig's JS templates (http://ejohn.org/blog/javascript-micro-templating/ http://ejohn.org/blog/javascript-micro-templating/). When time permits we'll move to the now official jQuery templates (http://api.jquery.com/jquery.tmpl/ http://api.jquery.com/jquery.tmpl/). Most website frontends consume the API directly in template while still server-side. Some go further and leverage the API from JS/XHR to make pages more interactive.
- StavrosK 16y agoI see, thank you very much for the explanation.
- getsat 16y ago> We use your typical web app SHA1 hash with generated salt. Oh, no! casts summon tptacek Actually, in his absence, I'll link to this recent topic on HN: http://news.ycombinator.com/item?id=2004833 http://news.ycombinator.com/item?id=2004833 This is particularly relevant given the recent complete and utter ownage of Gawker and friends. Had they been using SHA1 (whether or not they had a fancy, home-grown salting/obscurity system to use with it) instead of DES, the result would have been basically the same. tl; dr: SHA1 is FAST. Do NOT use it. Use bcrypt. Please.
- JoelSutherland 16y agoKris is talking about authentication, not password storage.
- getsat 16y agoAh, you're right. I was scanning the comments and came across "SHA1 + salt" and overreacted. Sorry.
- KrisJordan 16y agoYes, and thanks to tptacek's advice on HN we have used bcrypt for passwords from the get go.