Demo Discussion
Forum Config Examples Contributions Vulnerabilities
  Discussion forum about ELOG, Page 265 of 808  Not logged in ELOG logo
New entries since:Thu Jan 1 01:00:00 1970
ID Date Icon Author Author Email Category OS ELOG Version Subjectdown
  68357   Tue Jul 12 20:53:03 2016 Reply Jason Stitancomp@hotmail.caQuestionWindowsV3.1.1-3f311c5Re: Using Reply option

Works Great. Thanks Andreas

Andreas Luedeke wrote:

Preset on reply Author = $long_name
Cheers, Andreas

Jason S wrote:

Forgive me I'm not incredibly Elog savy yet.

A little backround about this log book -  I have our log set up as individual user names.  The log book is designed for entrys to be made when a process shutdown needs to be bypassed.  The operator will create an entry and submit it.  Then a supervisor will come in after and review/approve it.  I've removed the edit function,  but left the "Reply" option available for the supervisor to go into the same entry and check off the "Reviewed" attribute.  When the reviewed attribute is checked off, even with a different logged in author the next entry ID still shows the original author that put in the entry rather then the author who clicked reviewed.  If there a way to get around this?

[Process Bypass]
Comment = (Not in use right now, currently developing)
Attributes = Author, Date/Time of Bypass, Equipment Name, Device Tag, Supervisor Sign-off,
Moptions Supervisor Sign-off = Reviewed
List Menu commands = New, Find, Logout
Menu Commands = New, Find, Reply, Logout
Required Attributes = Date/Time of ByPass, Equipment Name, Device Tag
 

 

 

 

  522   Mon Apr 5 09:28:19 2004 Reply Stefan Rittstefan.ritt@psi.chInfoWindows2.5.2Re: Using Javascript files
> I develop multiple client server apps and web apps deployed on intranets. I
> need my users to send me bugs with screenshots attached.

Nice idea. I was looking myself for a way to automatically attach screenshots,
but I haven't found a clever way yet. One problem with attachments I found is
that it is not possible to preset the attachment text box with a file name
because this would open up a big security hole. So a malicious web page would
preset the attachment box with a file name pointing to some local password file,
then hide the box somwhere by using a tiny font etc. So if someone presses
"submit", the secret file would automatically transferred to the remote site.
Now I don't know if this can be bypassed with JavaScript.
 
> Now apparently that wasn't fully working or at least you couldn't bring up
> multiple alerts. Has that been fixed, or is it just a problem with alerts?

The JavaScript you supply simply gets copied to the web page and executed. There
are no limitations of any kind from the elog system there. So if you have
problems, it's most likely a JavaScript problem. I found it very useful to use
the Venkman debugger (http://www.mozilla.org/projects/venkman/) which can run
inside Mozilla based browsers.

> Can I write a url that has my attributes, plus a short js script that just
> adds an attachment?

It should be in principle possible, limited maybe only with the security note I
wrote above. If you get anything working, I would appreciate if you could add
this to the "contributions" section, so that other people can benefit from this.
  544   Fri May 21 14:43:09 2004 Reply Stefan Rittstefan.ritt@psi.ch Windows2.5.2Re: User/Admin privlege question
> For some reason if I define a "login user" that is allowed the configure
> option he is also allowed to change the configuration file. According to the
> documentation it seems like this should NOT be the case. Any ideas as to
> what the problem might be? 

Unfortunately I cannot reproduce your problem. This leaves few possibilites:

- any login user CAN change his/her full name, email address etc. but only admin
users can change ALL OTHERS as well. Admin users should see a "change elogd.cfg"
button on the config page, whil normal users will not

- are you sure you logged out as admin user and loggin in again as non-admin
user? Under some circumstances, the browser keeps old cookies which can confuse
things. Best is if you delete all browser cookies and try again (Tools/Internet
Options/Delete Cookies in IE).

- Stefan
  567   Fri Jul 2 15:18:20 2004 Warning Alexandre Camsonnecamsonne@jlab.orgBug reportLinux2.5.2 - 2.5.3Re: User/Admin privlege question
Hi, 
I also have this problem, when a non admin user logs in he does not have access to
the config file but if he logs out he can then access the config file as non logged
user.
I also tried to upgrade to version 2.5.3 but running under this version does not ask
for passwords so I reverted to 2.5.2.

Besides these few details, your software is great !

Thank you,

Alexandre

> > For some reason if I define a "login user" that is allowed the configure
> > option he is also allowed to change the configuration file. According to the
> > documentation it seems like this should NOT be the case. Any ideas as to
> > what the problem might be? 
> 
> Unfortunately I cannot reproduce your problem. This leaves few possibilites:
> 
> - any login user CAN change his/her full name, email address etc. but only admin
> users can change ALL OTHERS as well. Admin users should see a "change elogd.cfg"
> button on the config page, whil normal users will not
> 
> - are you sure you logged out as admin user and loggin in again as non-admin
> user? Under some circumstances, the browser keeps old cookies which can confuse
> things. Best is if you delete all browser cookies and try again (Tools/Internet
> Options/Delete Cookies in IE).
> 
> - Stefan
  573   Wed Jul 7 17:43:22 2004 Reply Stefan Rittstefan.ritt@psi.chBug reportLinux2.5.2 - 2.5.3Re: User/Admin privlege question
> I also have this problem, when a non admin user logs in he does not have access to
> the config file but if he logs out he can then access the config file as non logged
> user.

If he logs out, how can he access a logbook at all? He should be presented a login
screen, nothing else...

> I also tried to upgrade to version 2.5.3 but running under this version does not ask
> for passwords so I reverted to 2.5.2.

Better first let's fix this problem. Under what circumstances does 2.5.3 not ask for
passwords? Maybe you can get the newest version from CVS (see download page) and try
again, I had problems when using the -DHAVE_CRYPT functionality, but I guess you did not
have that, do you?

So once you tried the latest snapshot, and still have problems, describe them carefully,
send me your configuration file, and I will have a look.

- Stefan
  644   Tue Aug 3 05:31:08 2004 Reply Alexandre Camsonnecamsonne@jlab.orgBug reportLinux2.5.2 - 2.Re: User/Admin privlege question
Dear Stefan,
I eventually tried the latest version from the CVS. 
And it is odd because like when I tried version 2.5.3, it is like it ignores
the passwd file. I guess I must have a problem in my cfg file.
So I can't really test if 2.5.3 or 2.5.4 have the same problem.

Right now I'm still using 2.5.2 which works fine, if i log out and click on
the logbook tab. I get the page which ask for the username and password. The
thing is I don't get returned to the username/password when I hit log out. I
arrive in the state you can see in the unlogged.jpg.
From here if can go into all the logbooks as long as I don't hit the
logbooks tab and worse I can access to all the config files.

Is there something really badly configured in my config file ? I guess it is
not supposed to work that way.

Thank you,

Alexandre
Attachment 1: logged.jpg
logged.jpg
Attachment 2: notlogged.jpg
notlogged.jpg
Attachment 3: elogd.cfg
[global]
logbook tabs = 1
SMTP host = smtpmail.jlab.org
port = 8080
main tab = Logbooks
group general = runliste,issues,procurement,minutes
group detector = proton, calorimeter,neutron
group daq = coda, VME
group Slowcontrol = LED,XY,ADC,HV
group Software=offline
Guest menu commands = Back, Find, Login, Help
Admin user = camsonne
Self register = 3
Password file = passwd.txt
Logfile = dvcs.log
Logging level = 3
Display mode = threaded
Menu commands = New, Reply, Find ,Login, CSV Import, Logout, Login, Help

[Offline]
Theme = default
Password file = passwd.txt
Comment = DVCS Offline software
Attributes = Author, Type,Subject
Preset Author = $long_name
Options Type = idea, bug, misc, to do 
Required Attributes = Author, Type
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help, CSV Import, Logout, Login
Guest menu commands = Back, Find, Login, Help
Email format= 15
Restrict edit = 1

[HV]
Theme = default
Password file = passwd.txt
Comment = HV
Attributes = Author, Type,Subject
Options Type = settings,hardware,software,remark
Preset Author = $long_name
Required Attributes = Author, Type
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help

[ADC]
theme = default
Password file = passwd.txt
Comment = ADC
Attributes = Author, Type,Subject
Options Type = settings,hardware change,software change,remark
Preset Author = $long_name
Required Attributes = Author, Type
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help

[minutes]
Theme = default
Password file = passwd.txt
Comment = Minutes
Attributes = Author,Subject
Preset Author = $long_name
Required Attributes = Author,Subject
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help
Email format= 15
Restrict edit = 1

[neutron]
Theme = default
Comment = Neutron veto
Password file = passwd.txt
Attributes = Author, Type,Subject
Options Type = new, runs, problem, misc 
Preset Author = $long_name
Required Attributes = Author, Type, Number
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help
Email format= 15

[procurement]
Theme = default
Password file = passwd.txt
Comment = Pending issues
Attributes = Author, Type,Subject
Preset Author = $long_name from $remote_host
Options Type = Nice to have,Ordered,Received,Needed
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help
Email format= 15
Restrict edit = 1

[issues]
Theme = default
Password file = passwd.txt
Comment = Pending issues
Attributes = Author, Type,Subject
Preset Author = $long_name from $remote_host
Options Type = Idea,Problem, to do, not forget
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help
Email format= 15
Restrict edit = 1

[runliste]
Theme = default
Password file = passwd.txt
Comment = DVCS runliste
Attributes = Author, Type,Subject, Number
Preset Author = $long_name
Options Type = cosmics calo, led calo, pedestal calo, junk calo, misc, cosmics pa, led pa, pedestal pa, junk pa,cosmics, led, pedestal
Required Attributes = Author, Type, Number
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help, CSV Import, Logout, Login
Guest menu commands = Back, Find, Login, Help
Email format= 15
Restrict edit = 1
Use Email Heading = New entry added to runliste related to run $Number
Protect Selection page = 1

[LED]
Theme = default
Password file = passwd.txt
Comment = LED
Attributes = Author, Type,Subject
Options Type = settings,hardware change,software change,remark
Preset Author = $long_name
Required Attributes = Author, Type
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help

[XY]
Theme = default
Password file = passwd.txt
Comment = XY
Attributes = Author, Type,Subject
Options Type = hardware, software, misc 
Preset Author = $long_name from $remote_host
Required Attributes = Author, Type, Number
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help

[test]
Theme = default
Password file = passwd.txt
Comment = test
Attributes = Author, Type,Subject, Number
Options Type = cosmics, led, misc 
Required Attributes = Author
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help


[dvcs]
Theme = default
Password file = passwd.txt
Comment = dvcs
Attributes = Author, Type,Subject, Number
Options Type = cosmics, led, misc 
Required Attributes = Author, Type, Number
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help

[proton]
Theme = default
Comment = Proton array
Password file = passwd.txt
Attributes = Author, Type,Subject
Options Type = new, problem, misc 
Preset Author = $long_name
Required Attributes = Author, Type, Number
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help

[calorimeter]
Password file = passwd.txt
Theme = default
Comment = Calorimeter logbook
Attributes = Author, Type,Subject
Options Type = new, problem, misc 
Preset Author = $long_name
Required Attributes = Author, Type, Number
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help
Email format= 15

[coda]
Password file = passwd.txt
Theme = default
Comment = CODA
Attributes = Author, Type,Subject
Options Type = new, problem, misc 
Required Attributes = Author, Type, Number
Preset Author = $long_name
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help
Email format= 15

[vme]
Password file = passwd.txt
Theme = default
Comment = vme
Attributes = Author, Type,Subject
Options Type = new, problem, misc 
Required Attributes = Author, Type, Number
Page Title = ELOG - $subject
Reverse sort = 1
Quick filter = Date, Type
Menu commands = Back, New, Edit, Delete, Reply, Find, Help
Guest menu commands = Back, Find, Login, Help
Attachment 4: notloggedcfg.jpg
notloggedcfg.jpg
Attachment 5: notloggedcfgg.jpg
notloggedcfgg.jpg
  646   Tue Aug 3 12:46:55 2004 Reply Stefan Rittstefan.ritt@psi.chBug reportLinux2.5.2 - 2.Re: User/Admin privlege question
I just see your [global] part of elogd.cfg, could you send me the complete file?

What you also could try is to delete all cookies stored in your browser. The way
cookies are formed changed between 2.5.2 and 2.5.3, so the system could be
confused by old cookies.

- Stefan
  649   Tue Aug 3 14:51:34 2004 Reply Alexandre Camsonnecamsonne@jlab.orgBug reportLinux2.5.2 - 2.Re: User/Admin privlege question
The elogd.cfg is attached in the previous message as attachement 3. Sorry it is a
little bit buried between pictures.
The reason I put the picture of the global elogd.cfg is to show that the not logged
user has access to elogd.cfg which is some kind of trouble...

> I just see your [global] part of elogd.cfg, could you send me the complete file?
> 

Hi I tried to remove the cookies and it still did not ask for password under 2.5.4.
Has the password file format changed between 2.5.2 and 2.5.3 ?

> What you also could try is to delete all cookies stored in your browser. The way
> cookies are formed changed between 2.5.2 and 2.5.3, so the system could be
> confused by old cookies.
> 
> - Stefan
ELOG V3.1.5-3fb85fa6