News:

SMF 2.1.6 has been released! Take it for a spin! Read more.

Main Menu

Security questions bug

Started by efk, July 10, 2021, 05:03:11 PM

Previous topic - Next topic

efk

Some new users on my forum are getting problem because of bad security question texture or don't know how to call it, so if I set security question to be
Enter all symbols you see (remove letters and numbers (so everything else except letters and number)): q#u^e@s&t(i+o5n
SMF result, visible security question for every user who need to answer on security question will be
q#u^e@s&t(i+o5n:

So as Administrator I am going to set security question q#u^e@s&t(i+o5n and the result visible to newly registered member is q#u^e@s&t(i+o5n:

And so instead of this correct answer #^@&(+  user is going to do mistake and answer this #^@&(+:

So how to fix this, and why does SMF question is with : and not with ?  ??? This sounds like a bad logic to me, possible wrong string used on wrong place.

a10

Funny trap. Not encountered it, not using any symbols as answers.
Indeed, questions should appear in the reg form exactly as written, nothing added.
2.0.19, php 8.0.30, MariaDB 10.6.18. Mods: Contact Page, Like Posts, Responsive Curve, Search Focus Dropdown, Add Join Date to Post.
Stand with 🇺🇦

Kindred

Not actually a bug....  just an incident because of the specificity of your odd question.

Resolution?
Use a different question, since you know that the query ends with :
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

GL700Wing

Life doesn't have to be perfect to be wonderful ...

Slava
Ukraini!
"Before you allow people access to your forum, especially in an administrative position, you must be aware that that person can seriously damage your forum. Therefore, you should only allow people that you trust, implicitly, to have such access." -Douglas

efk

Quote from: a10 on July 10, 2021, 06:04:47 PM
Funny trap. Not encountered it, not using any symbols as answers.
Indeed, questions should appear in the reg form exactly as written, nothing added.
Exactly, its logical...

Quote from: Kindred on July 10, 2021, 06:15:14 PM
Not actually a bug....  just an incident because of the specificity of your odd question.

Resolution?
Use a different question, since you know that the query ends with :
I know its not a bug. As SMF fan I would often use word "hole in the system", but that would be too dramatic.
The thing is this string has no purpose and no reason to be there, should it be fixed line in 2.0.19? I am Junior QA software tester without experience, from what they taught us things like are supposed to be reported and fixed. In this situation you have a tool,
Administrator does his part and all is expected to be flawless,
User does his part and it should work flawless,
SMF response >> Nope, you are wrong mister User, you are not allowed to answer to that question correctly.
User is thinking >> But why, I did everything which is requested.
SMF last response >>


To sum, my security question is absolutely normal and it should work without causing problems

shadav

Quote from: GL700Wing on July 10, 2021, 07:44:33 PM
Tip/Trick : Remove colon added to end of Verification Question
did you check this?
if the issue is just the : then what gl700wing posted will remove it and if you scroll down a few posts I also posted how to remove it from the verification image part too

efk

Somehow missed to read, checked and will do. Thanks all.

About verification image part, I'm not using it and not sure how reliable it is and from my experience its painful for users to use it.

Is it possible to remove such line in future SMF updates?

Illori

Quote from: efk on July 11, 2021, 05:01:48 AM
Is it possible to remove such line in future SMF updates?

we really try not to make changes like this, even if they seem small, they may have other effects and other themes may not get the change made in them anyway.

if this is an issue in SMF 2.1, you can suggest to have this changed there.

Advertisement: