Open sourcing pouet.net ?
category: offtopic [glöplog]
I'm just reminded by the daytime TV dramas about negligent parents trying to get parental control over the kids they abandoned into adoption programmes that worked well -until this shit happens.
Quote:
By opensourcing Pouet 0.9 without any further code audition, you have been acting irresponsibly and stubbornly in worst possible way.
absolutely.
Quote:
if you're worried about sql injections then audit the code and fix them before they get a chance to be exploited.
well, uhm, no? how about not making the code open-source in the first place? i spent too much time adding prods to risk someone coming around and deleting them just to prove a point.
bloody open-source idiocy.
Well, I clearly want the whole data too, in my new job I'm displaying (big)data as nice stats, so I really want to play with pouet.net data too :)
Quote:
if you're worried about sql injections then audit the code and fix them before they get a chance to be exploited.
That's exactly the "plz fix mah problems" attitude I was referring to earlier. Why should somebody fix your mistakes?
Sure, in an healthy OSS project this isn't really a problem. But forcing the issue like this is the wrong approach :-)
You guys are aware that the pouët database is backed up regularly, right?
Quote:
if you're worried about sql injections then audit the code and fix them before they get a chance to be exploited.
the bugs were already there, now they're public. yeah, it could be handled better. pre-audited, as suggested shitloads of times years ago.
but we are living in the now, and right now the code is out there open sourced.
and you have 2 options: you can sit on your chair, whine that it's all wrong until disaster strikes, or you can help improve the site you are using.
it's your option.
gargaj has already contributed a few sql injection patches a couple hours ago. that might hint you on what the best coarse of action might be for the site's future right now.
but we are living in the now, and right now the code is out there open sourced.
and you have 2 options: you can sit on your chair, whine that it's all wrong until disaster strikes, or you can help improve the site you are using.
it's your option.
gargaj has already contributed a few sql injection patches a couple hours ago. that might hint you on what the best coarse of action might be for the site's future right now.
do you really think somebody here will ever try to kill the DB ? seriously...
AND YES, BRING THE OLD DATA BACK!!! please. may be a .zip or public access to unexisting daily backups... lol.
to drunk to search the pony picture enhancing this discussion.
AND YES, BRING THE OLD DATA BACK!!! please. may be a .zip or public access to unexisting daily backups... lol.
to drunk to search the pony picture enhancing this discussion.
do you really think somebody here will ever try to kill the DB ? seriously...
The quesion is not if, the question is when.
The quesion is not if, the question is when.
bbcode is for jazzmusicians!
I doubt we'll ever release the full SQL dump, but monthly cleaned dumps of selected data, like CSV of prods or groups is def a good idea if people find it useful
mog, dfox: i get that you're angry at analogue for all this, and that you fully supported gargajs plans so you feel cut off aswell, so your pride might be preventing you from reasoning with me. but the world hasn't ended, the planet keeps rotating. and now you can either help or you can whine. and only one of those actions is productive as far as i see it.
I actually can't stop laughing, because I have the hard feeling you even believe what you say.
NEIN!
I WANT ALL THE FUCKIN DATA, POUET IS NOT TWITTER OR FACEBOOK :(
I WANT ALL THE FUCKIN DATA, POUET IS NOT TWITTER OR FACEBOOK :(
CSV xD
mog: well, have a nice life then.
analogue: i agree with rez, full data is always better. i just checked the account.php though and seems there might still be passwords and emails on the db side though, not completly on sceneid as i was thinking, so definitely needs some privacy sanitation on the dump.
analogue: i agree with rez, full data is always better. i just checked the account.php though and seems there might still be passwords and emails on the db side though, not completly on sceneid as i was thinking, so definitely needs some privacy sanitation on the dump.
so let me get this straight - analogue was afraid that gargaj might claim "ownership" of pouet 2.0, and in result he's behaving like a fucking dictator himself. i am really not comfortable with this, considering how much of my lifetime i have put into the content-side of pouet.
Quote:
or you can help improve the site you are using
Nothing like trying to crowdsource the people that just got the feeling they were shafted. Have the action movies of the 80s learned you nothing?
ha yes sorry, thank you ps for pointing it, of course the db need some "anonymization" with users private info :)
Quote:
the content-side of pouet
Yes. Exactly that. Where's the Google Checkout equivalent for the end users, or do they have to magically open source that into existence before Analogue tears down the site because he feels like that? :)
Yes, fucking data please. Those things arent copyrighted by nazis (kb should be happy now), and trying to get power on this shitty site using percentage years of week-end development is REALLY pointless, considering what its about, big part of prods here took way more time than your scheisse dictature. stop.
numtek: the holes are been here for years, any script-kid may always been able to broke it with stupid haxxor plugins, but thing is, there is no point. no reward, nothing. thinking this is nazi as well.
numtek: the holes are been here for years, any script-kid may always been able to broke it with stupid haxxor plugins, but thing is, there is no point. no reward, nothing. thinking this is nazi as well.
ps: I'm not angry at all. I'm just pointing out the fact that the way things are being handled right now are not really helping to get anyone on your or analogues site - at least not in my book.
I have enough stuff and projects for myself and don't plan to be pressured to help out fixing a rushed code release made because of overreacting about a non-issue. I'm not asking you to repaint my car because I thought washing it with rocks was a good idea, am I?
I have enough stuff and projects for myself and don't plan to be pressured to help out fixing a rushed code release made because of overreacting about a non-issue. I'm not asking you to repaint my car because I thought washing it with rocks was a good idea, am I?