[Opensim-dev] secure_inventory_server ??
Charles Krinke
cfk at pacbell.net
Fri Jul 25 03:20:59 UTC 2008
Thanks, Lulurun. That helps some.
I believe the concern I have is the support of our users on the #opensim IRC channel. If there are settings to OpenSim that are *not* in OpenSim.ini.example and someone sets them, then support gets more difficult.
At this point, I am merely trying to suggest that any config settings that anyone might use be entered in OpenSim.ini.example. Additionally a couple of comments that describe when one might want to use these settings would help our users move forward.
Charles
----- Original Message ----
From: liu xiaolu <lulurun at gmail.com>
To: opensim-dev at lists.berlios.de
Sent: Thursday, July 24, 2008 8:04:24 PM
Subject: Re: [Opensim-dev] secure_inventory_server ??
That option is avaliable from 5592, it is just a temporary thing.
To explain the situation simply:
1. old inventory server accepts any request without check the use identity, this causes a problem that everyone's inventory information can be easily modified by other people who even do not know your password.
2. secure_inventory_server accepts request by checking a valid session_id, so every inventory request needs to be attached a session_id.
3. then both of the regionserver and the inventoryserver have to be changed:
3.1 regionserver adds user's "session_id" to inventory CRUD requests
3.2 secureinventoryserver expects the request data contains a "session_id"
4. so the latest regionserver do not work with non-secure inventoryserver any more.
the option enables people who are using the latest regionserver, but want to connect to a non-secure inventoryserver - they can set "use_secure_invnetory" to false in OpenSim.ini
2008/7/25 Charles Krinke <cfk at pacbell.net>:
I am hearing about a new OpenSim.ini setting called secure_inventory_server and am told it is not in OpenSim.ini.example. I believe all settings for OpenSim should be in OpenSim.ini and have a default, which in this case could be either true, or false, I would think.
Can someone please help us understand what this setting is, what it does when set to false, what it does when set to true and perhaps consider adding at least a default for this setting in OpenSim.ini.example?
Charles
_______________________________________________
Opensim-dev mailing list
Opensim-dev at lists.berlios.de
https://lists.berlios.de/mailman/listinfo/opensim-dev
--
Lulurun
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://opensimulator.org/pipermail/opensim-dev/attachments/20080724/2641268c/attachment-0001.html>
More information about the Opensim-dev
mailing list