<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://2007.oscms-summit.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>security</title>
 <link>http://2007.oscms-summit.org/taxonomy/term/89/feed</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Using node_access in Drupal 5</title>
 <link>http://2007.oscms-summit.org/node/205</link>
 <description>&lt;p&gt;A comprehensive overview of Drupal&#039;s system for securing nodes. This session will cover:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt; How the database is constructed.
&lt;li&gt; How the query is rewritten.
&lt;li&gt; How it interacts with other Drupal access (particularly permission flags, the published flag and hook_access)
&lt;li&gt; The API
&lt;li&gt; How to put all this together to write a simple access control module.
&lt;/ul&gt;
</description>
 <comments>http://2007.oscms-summit.org/node/205#comments</comments>
 <category domain="http://2007.oscms-summit.org/taxonomy/term/5">Drupal</category>
 <category domain="http://2007.oscms-summit.org/taxonomy/term/106">api</category>
 <category domain="http://2007.oscms-summit.org/taxonomy/term/107">developer</category>
 <category domain="http://2007.oscms-summit.org/taxonomy/term/105">node access</category>
 <category domain="http://2007.oscms-summit.org/taxonomy/term/89">security</category>
 <pubDate>Mon, 12 Feb 2007 08:44:37 -0800</pubDate>
 <dc:creator>merlinofchaos</dc:creator>
 <guid isPermaLink="false">205 at http://2007.oscms-summit.org</guid>
</item>
<item>
 <title>Improving Drupal user login security practices</title>
 <link>http://2007.oscms-summit.org/node/150</link>
 <description>&lt;p&gt;Most Drupal-based sites use password-based authentication.  This session will discuss and design proposals for improving the current practices.  Current ideas include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Abandoning long-life PHP session cookies&lt;/li&gt;
&lt;li&gt;Best practices for persistent login (a.k.a. &quot;Remember Me&quot;) cookies&lt;/li&gt;
&lt;li&gt;Not distributing initial account passwords via email&lt;/li&gt;
&lt;li&gt;Supporting required instead of optional password changes&lt;/li&gt;
&lt;li&gt;How SSL support should be integrated and configured&lt;/li&gt;
&lt;li&gt;Preventing hijacking of mixed plaintext/SSL sessions&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href=&quot;http://2007.oscms-summit.org/node/150&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://2007.oscms-summit.org/node/150#comments</comments>
 <category domain="http://2007.oscms-summit.org/taxonomy/term/5">Drupal</category>
 <category domain="http://2007.oscms-summit.org/taxonomy/term/90">login</category>
 <category domain="http://2007.oscms-summit.org/taxonomy/term/89">security</category>
 <pubDate>Sun, 11 Feb 2007 08:01:16 -0800</pubDate>
 <dc:creator>bjaspan</dc:creator>
 <guid isPermaLink="false">150 at http://2007.oscms-summit.org</guid>
</item>
</channel>
</rss>
