[Board] Fwd: OpenGIS competition

Massimiliano Cannata massimiliano.cannata at supsi.ch
Mon Aug 1 13:24:01 PDT 2016


FYI,

Some problems seems to be reported in creating an osgeoid. See forwarded
mail here below for details.

Best
Maxi

Hi,

Thanks for running the competition.

Please find attached my submissions to your competition at
https://wiki.osgeo.org/wiki/UN_OpenGIS_logo_contest. I am sending it
directly because I had trouble registering. The link supplied in the
registration confirmation email didn't succeed - even when I added the
https: scheme at the beginning.

Someone, probably you from IP address 118.148.127.135, has requested
an account "Grantps" with this email address on OSGeo Wiki.

To confirm that this account really does belong to you on OSGeo Wiki,
open this link in your browser:

//wiki.osgeo.org/index.php?title=Special:RequestAccount&action=confirmemail&wpEmailToken=066...5eb

[token redacted by me for this email]

If the account is created, only you will be emailed the password.
If this is **not** you, do not follow the link.
This confirmation code will expire at 07:38, 31 August 2016.

A couple of other issues were encountered:

1) The terms of service I agreed to are not present yet ;-)
https://wiki.osgeo.org/wiki/OSGeo_Wiki:Terms_of_Service

There is currently no text in this page. You can search for this page title
<https://wiki.osgeo.org/wiki/Special:Search/Terms_of_Service> in other
pages, or search the related logs
<https://wiki.osgeo.org/index.php?title=Special:Log&page=OSGeo_Wiki:Terms_of_Service>,
but you do not have permission to create this page.

2) When I tried registering using the return link (which was not a link but
plain text) I got a 404. Additionally, the page reflected back the content
of the url. Was it sanitised first? If not it is probably best to either
add sanitisation or not reflect it back at all to reduce risk of cross-site
scripting attacks. Probably doesn't create any risk in this case but
probably best not to do that in general.

I'm offering this feedback in the hope that it might be helpful.

All the best,

Grant
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.osgeo.org/pipermail/board/attachments/20160801/028fe60c/attachment.html>


More information about the Board mailing list