11 ms·
Show HN: I made CMS less than 15 kilobytes, flat file
https://github.com/turboblack/HamsterCMS https://github.com/turboblack/HamsterCMS
http://web1.0hosting.net/ http://web1.0hosting.net/ - free hosting based on this CMS
- lsh0 2y agooh - some of those designs in the examples (quark, 0832) take me back. Pure nostalgia. Thank you.
- Turboblack 2y agoI'm glad you like it, there are already 99 templates on the hosting
- synergy20 2y agocan i hide all the posts before login,which is what cms good for,else it looks similar to SSG to me,thanks
- Turboblack 2y agoThank you very much for your feedback, I really appreciate it
- kopakobana 2y agoStarred you too, pretty nice CMS and templates!
- Turboblack 2y agoI'm very glad that you liked it, thank you for your feedback
- noufalibrahim 2y agoThose little GIFs bring a tear to my nostalgic eyes.
- Turboblack 2y agoWelcome to the community ;-)
- zoobab 2y agoThe "Under construction" one :-)
- joobadze 2y ago[flagged]
- Turboblack 2y agothanks for the feedback, welcome to the community, by the way, cms was tested under dos, several enthusiasts sent me screenshots https://i.imgur.com/7uoP1lO.jpeg https://i.imgur.com/7uoP1lO.jpeg https://i.imgur.com/rZON07e.jpeg https://i.imgur.com/rZON07e.jpeg https://i.imgur.com/soMy1Dp.jpeg https://i.imgur.com/soMy1Dp.jpeg
- lifthrasiir 2y agoAs who has endured the old Web 1.0 era with PHP, I can immediately see that the author didn't have any benefit of hindsight: no error handling, no XSS protection, no CSRF protection, no atomic file writing, no correct permission in the data directory (which means that some settings are still required depending on your webserver), no real way to change password which is built into admin.php, no constant-time comparison on login, no correct template handling (it may or may not recursively expand included files depending on the order!), unlimited writes to the session even when credentials do not match, and of course no protection against any attempt to use fopen wrappers after login. And the supposed "content" management system doesn't allow any file uploading. The author needs to be a lot more careful about security at the very least. To be precise, PHP is not the culprit here, but does enable lots of easy ways to make your program immediately insecure due to its interface and one has to learn how to avoid them systematically.
- Turboblack 2y agothank you very much for your feedback, I am very grateful to you for studying the script in detail, I have not had such detailed criticism from anyone before. I will gradually take your comments into account, because what I do is very important to me, and I also want it to be useful for others. useful and painless. If you can help me at least a little with solutions - I will really look forward to your letter downgrade@meta.ua
- lawn 2y agoReplying with a ChatGPT response doesn't quite convey sincerity I'd say.
- Turboblack 2y agoWhy are you so aggressive?
- lawn 2y agoThere's no aggression meant in my comment, just an attempt to give some feedback in how you might be perceived when you respond in a certain way.
- ulrischa 2y agoNice but calling this a CMS is a little bit over the top
- Turboblack 2y agoThe main thing is that the script does its job, right?
- KomoD 2y agoAre you commenting on your own posts from different accounts? kopakobana and joobadze only comment on and promote your things.
- Turboblack 2y agoThese guys have been using hosting for a long time, I asked them to support me. One is Georgian, the second is from Western Europe.
- deleted 2y ago[deleted]
- zoobab 2y agoYou miss a "webring" footer!
- Turboblack 2y agoThanks for the comment, I'll take it into account
- pjmlp 2y agoWhile the effort is welcomed, one has to start somewhere, this is more like a "Hello World CMS".
- Turboblack 2y agothe start is really very good, and there are already more than 300 registrations on the hosting.
- joobadze 2y ago[flagged]
- Turboblack 2y agoThank you