Dear List,

i am using sqwebmail for quite a long time now and everything
works fine. Now a guy from the "Webpage Development Office"
was asked to customize the html templates to fit the buisness look.
He trashed around in html templates a created a new site. now the
authentication does not work probably. here is the problem:

1. login authentication works, sqwebmail lets me in the folder view.

2. when i try to anything else like viewing an email/folder, creating an
email, prefernces or anything else. it throws me out telling me that
my session ran out of time.

I checked that the files

sqwebmail-curcnt
sqwebmail-ip
sqwebmail-timestamp

were created. content looks exactly like the files generated by the working
sqwebmail with default templates.

The Links the Development-Guy copied seem to be okay, here is an example:

http://our-server/cgi-bin/sqwebmail/login/philipp@;xxxx.net.authvchkpw/8C55E7
831CC9D269DCC1FD91E40936D6/1036499757?&form=folders

Altough i think that theres something wrong with the authenticaten-token. i
logged in the working version, copied a link and changed the
host-part to force it to use the new template and voila, it let me in.

Finally, i watched the access.log file from the webserver. the working
version produced this line:

80.132.250.182 - - [05/Nov/2002:13:38:25 +0100] "GET
[EMAIL PROTECTED]/7D239A08A27D5C68EE96107103
E27810/1036499890?folder=INBOX&newmsg=1&form=newmsg HTTP/1.1" 200 6494

The new template version created this one:

80.132.250.182 - - [05/Nov/2002:13:38:51 +0100] "GET
[EMAIL PROTECTED]/2336BB03532DF1B2E08
03FDA352CCD9C/1036499922?&newmsg=1&form=newmsg HTTP/1.1" 200 4540


I see that in the second version the folder-information is missing, but the
template-file hat the "&" in it.


I read the page at
http://www.firstpr.com.au/web-mail/SqWebMail/sqdocs/sqwebmail-SECURITY.html
but it didnt
helped me out. as you could see we are using vchkpw and its a sqwebmail
version 2.

I am lost at this point, could someone please give me a hint ?


Best Regards,
Philipp


Reply via email to