MythLogBot@irc.freenode.net :: #mythtv

Daily chat history

Current users (78):

aloril, amessina, Anssi, blahdodo, brfransen, Captain_Murdoch, ChanServ, Chutt, clever, coling, CyberJacob, dblain_, dekarl, dym, eharris, ElmerFudd, gary_buhrmaster, ghoti, gigem, gregbert, gregL, GreyFoxx, Guest88756, Guest98624, Hydr0p0nX, ikevin, J-e-f-f-A, jab416171, jams__, jheizer, jmcentee_, jnylen, joki, jpabq_, jpharvey, jst, jwr__, jya, kc, knightr, knowledgejunkie, lautriv_, libsci, logan-, mad_enz, markspieth, MitchCapper, MythBuild_, MythLogBot, nephyrin, peper03, poptix-, pppingme, purserj_, purserj__, raven42, rich0, Roklobotomy, saaki, seld, ShapeShifter499, sphery, sraue, stuartm, superm1, taylorr, tgm4883, tnewman, tonsofpcs, tris, unforgiven512, vincent43, wagnerrp, Warped, XDS2010, xris, _charly_, _iwc
Wednesday, April 20th, 2016, 00:31 UTC
[00:31:10] amessina (amessina!~amessina@unaffiliated/amessina) has quit (Quit: Konversation terminated!)
[00:33:04] hydroponx (hydroponx!~hydr@66-191-154-200.dhcp.mtgm.al.charter.com) has joined #mythtv
[00:36:01] Hydr0p0nX (Hydr0p0nX!~hydr@66.191.154.200) has quit (Ping timeout: 250 seconds)
[00:36:19] hydroponx is now known as Hydr0p0nX
[01:36:42] arescorpio (arescorpio!~arescorpi@131-192-114-200.fibertel.com.ar) has joined #mythtv
[01:38:13] joki (joki!~joki@p548615DE.dip0.t-ipconnect.de) has quit (Ping timeout: 268 seconds)
[01:43:25] joki (joki!~joki@p548617BD.dip0.t-ipconnect.de) has joined #mythtv
[02:20:23] peper03 (peper03!~peper03@mythtv/developer/peper03) has quit (Ping timeout: 250 seconds)
[02:25:16] peper03 (peper03!~peper03@mythtv/developer/peper03) has joined #mythtv
[02:58:56] mad_enz (mad_enz!~mad_enz@CPE00508b114c3e-CM00fc8d50aef0.cpe.net.fido.ca) has quit (Ping timeout: 244 seconds)
[04:10:03] joki (joki!~joki@p548617BD.dip0.t-ipconnect.de) has quit (Ping timeout: 240 seconds)
[04:10:39] joki (joki!~joki@p548617BD.dip0.t-ipconnect.de) has joined #mythtv
[04:13:00] seld (seld!~seld@h168n8-rny-a12.ias.bredband.telia.com) has quit (Ping timeout: 276 seconds)
[04:13:39] aloril (aloril!~aloril@dsl-tkubrasgw1-54fa3f-129.dhcp.inet.fi) has quit (Ping timeout: 276 seconds)
[04:16:00] seld (seld!~seld@217-209-54-168-no53.tbcn.telia.com) has joined #mythtv
[04:17:43] aloril (aloril!~aloril@dsl-tkubrasgw1-54fa3f-129.dhcp.inet.fi) has joined #mythtv
[04:21:49] mad_enz (mad_enz!~mad_enz@CPE00508b114c3e-CM00fc8d50aef0.cpe.net.fido.ca) has joined #mythtv
[05:07:40] arescorpio (arescorpio!~arescorpi@131-192-114-200.fibertel.com.ar) has quit (Excess Flood)
[05:36:03] letifosiferrari (letifosiferrari!~letifosif@lns-bzn-35-82-250-225-139.adsl.proxad.net) has joined #mythtv
[05:36:20] letifosiferrari (letifosiferrari!~letifosif@lns-bzn-35-82-250-225-139.adsl.proxad.net) has quit (Remote host closed the connection)
[05:36:47] letifosiferrari (letifosiferrari!~letifosif@216.207.42.140) has joined #mythtv
[05:52:50] Tobbe5178 (Tobbe5178!~asdf@h55n9-sv-a13.ias.bredband.telia.com) has joined #mythtv
[06:16:36] SteveGoodey (SteveGoodey!~steve@host5-81-230-128.range5-81.btcentralplus.com) has joined #mythtv
[06:59:36] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has quit (Remote host closed the connection)
[07:23:27] jst (jst!~quassel@198.199.94.175) has quit (Quit: No Ping reply in 180 seconds.)
[07:23:59] unforgiven512 (unforgiven512!~unforgive@freebsd-dev.unforgivendevelopment.com) has quit (Ping timeout: 244 seconds)
[07:24:34] jst (jst!~quassel@198.199.94.175) has joined #mythtv
[07:25:13] unforgiven512 (unforgiven512!~unforgive@freebsd-dev.unforgivendevelopment.com) has joined #mythtv
[07:26:27] willcooke (willcooke!~willcooke@willcooke.plus.com) has joined #mythtv
[07:26:28] willcooke (willcooke!~willcooke@willcooke.plus.com) has quit (Changing host)
[07:26:28] willcooke (willcooke!~willcooke@ubuntu/member/willcooke) has joined #mythtv
[07:50:30] ikevin (ikevin!~kevin@j-aime.etre.casse-couilles.org) has joined #mythtv
[08:01:21] Roklobotomy (Roklobotomy!~Dirkka@ppp118-209-128-112.lns20.mel8.internode.on.net) has joined #mythtv
[08:04:49] zz_CyberJacob is now known as CyberJacob
[08:05:29] stuarta: morning all
[08:11:20] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has joined #mythtv
[08:20:37] Roklobotomy: evening
[08:24:36] lautriv_ (lautriv_!~lautriv@funtoo/user/lautriv) has joined #mythtv
[08:29:17] SteveGoodey (SteveGoodey!~steve@host5-81-230-128.range5-81.btcentralplus.com) has quit (Quit: Konversation terminated!)
[08:31:24] cbovy (cbovy!~cbovy@2001:470:1f15:ff2::4f5) has joined #mythtv
[09:00:17] dekarl1 (dekarl1!~dekarl@mythtv/developer/dekarl) has joined #mythtv
[09:02:33] dekarl (dekarl!~dekarl@mythtv/developer/dekarl) has quit (Ping timeout: 240 seconds)
[09:21:48] dekarl1: cbovy: ty
[09:21:50] dekarl1 is now known as dekarl
[09:27:40] cbovy: dekarl: np. looking forward to your feedback.
[10:55:07] SteveGoodey (SteveGoodey!~steve@host5-81-230-128.range5-81.btcentralplus.com) has joined #mythtv
[11:29:18] Roklobotomy (Roklobotomy!~Dirkka@ppp118-209-128-112.lns20.mel8.internode.on.net) has quit (Ping timeout: 246 seconds)
[13:41:58] stuarta: bah, why does the channel-icon search use a POST by default. it should be using a get, as it's getting information.
[13:43:57] stuarta: damn POST's trigger rails CSRF protection
[13:45:46] stuarta: easy enough to turn off. but is that the right thing todo?
[13:47:34] jmcentee_: can you change mythtv to do a GET?
[13:48:00] stuarta: for future releases yes, but there are a lot of legacy installations that can't be broken
[13:48:28] stuarta: so the medium term plan is to implement versioning in the api with old requests going to v1 and newer ones to v2 etc
[13:50:23] stuarta: on the other had, despite these being POST requests, the methods being called don't modify any data
[13:50:36] stuarta: except maybe submit ;-)
[13:53:30] rich0 (rich0!~quassel@gentoo/developer/rich0) has quit (Remote host closed the connection)
[14:03:26] jmcentee_: turning off CSRF protection just doesn't feel like the right thing to do to me, when it is on the internet. Therefore outside of the usual mythtv security advice (e.g. local network not on the internet)
[14:05:18] stuarta: well the current implentation has none :(
[14:06:08] stuarta: the thing is, the way's it's implemented in rails we are missing the client side bits of
[14:06:57] stuarta: since the POST is meant to be the submission of a form, which came from the html page.
[14:07:17] stuarta: when rendering the html page, you include the tokens so the POST will pass CSRF
[14:07:27] stuarta: but we never render a page in the first place
[14:07:30] gregL (gregL!~greg@cpe-74-76-121-109.nycap.res.rr.com) has quit (Ping timeout: 244 seconds)
[14:07:41] stuarta: the client just fires off a post with the query it has
[14:07:55] stuarta: which is just butt ugly
[14:09:01] stuarta: thus the client never has the CSRF tokens it requires
[14:09:11] stuarta: some background reading http://api.rubyonrails.org/classes/ActionCont . . . tection.html
[14:12:20] cbovy (cbovy!~cbovy@2001:470:1f15:ff2::4f5) has quit (Quit: Leaving)
[14:14:50] jmcentee_: It's you looking after the server.
[14:14:56] stuarta: indeed
[14:15:14] stuarta: i will have to have a think on the best way to handle it long term
[14:16:41] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has quit (Ping timeout: 250 seconds)
[14:17:38] jmcentee_: Is it a global turn on/off or can you let a whitelist of POST cammands though?
[14:17:58] jmcentee_: /though/through/
[14:19:26] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has joined #mythtv
[14:28:35] rich0_ (rich0_!~quassel@gentoo/developer/rich0) has joined #mythtv
[14:41:07] Jordack (Jordack!~Jordack@75-151-31-172-Michigan.hfc.comcastbusiness.net) has joined #mythtv
[14:48:09] rich0_ is now known as rich0
[15:06:23] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has quit (Ping timeout: 244 seconds)
[15:21:40] gedakc (gedakc!~gedakc@d162-157-118-249.abhsia.telus.net) has joined #mythtv
[15:23:16] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has joined #mythtv
[15:27:39] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has quit (Ping timeout: 246 seconds)
[15:43:12] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has joined #mythtv
[16:16:30] Steve-Goodey (Steve-Goodey!~steve@host5-81-230-128.range5-81.btcentralplus.com) has joined #mythtv
[16:29:59] stuarta: jmcentee_: unsure yet, will consider it later
[16:44:12] letifosi_ (letifosi_!~letifosif@lns-bzn-35-82-250-254-212.adsl.proxad.net) has joined #mythtv
[16:45:03] gregL (gregL!~greg@cpe-74-76-121-109.nycap.res.rr.com) has joined #mythtv
[16:48:11] letifosiferrari (letifosiferrari!~letifosif@216.207.42.140) has quit (Ping timeout: 244 seconds)
[16:48:47] letifosi_ (letifosi_!~letifosif@lns-bzn-35-82-250-254-212.adsl.proxad.net) has quit (Ping timeout: 250 seconds)
[17:10:06] cbovy (cbovy!~cbovy@2001:470:1f15:ff2:39b8:2094:fdc6:79dd) has joined #mythtv
[17:41:55] gedakc (gedakc!~gedakc@d162-157-118-249.abhsia.telus.net) has quit (Quit: Leaving)
[17:51:27] gedakc (gedakc!~gedakc@d162-157-118-249.abhsia.telus.net) has joined #mythtv
[17:51:35] cbovy (cbovy!~cbovy@2001:470:1f15:ff2:39b8:2094:fdc6:79dd) has quit (Read error: No route to host)
[17:56:06] cbovy (cbovy!~cbovy@2001:470:1f15:ff2:39b8:2094:fdc6:79dd) has joined #mythtv
[19:03:07] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has quit (Ping timeout: 250 seconds)
[19:10:55] Steve-Goodey (Steve-Goodey!~steve@host5-81-230-128.range5-81.btcentralplus.com) has quit (Ping timeout: 250 seconds)
[19:11:45] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has joined #mythtv
[19:15:32] jpharvey (jpharvey!~jpharvey@95.149.163.88) has joined #mythtv
[19:18:09] gedakc (gedakc!~gedakc@d162-157-118-249.abhsia.telus.net) has quit (Quit: Leaving)
[19:27:49] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has quit (Ping timeout: 250 seconds)
[19:38:01] Steve-Goodey (Steve-Goodey!~steve@host5-81-230-128.range5-81.btcentralplus.com) has joined #mythtv
[19:42:27] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has joined #mythtv
[19:45:17] mad_enz (mad_enz!~mad_enz@CPE00508b114c3e-CM00fc8d50aef0.cpe.net.fido.ca) has quit (Ping timeout: 276 seconds)
[19:49:38] mad_enz (mad_enz!~mad_enz@CPE00508b114c3e-CM00fc8d50aef0.cpe.net.fido.ca) has joined #mythtv
[19:52:28] tonsofpcs (tonsofpcs!mythbuntu@2001:470:e0b2:1:1528:2d93:4397:7ba7) has quit (Changing host)
[19:52:28] tonsofpcs (tonsofpcs!mythbuntu@rivendell/member/tonsofpcs) has joined #mythtv
[20:11:09] brfransen (brfransen!~brfransen@71.11.51.80) has quit (Ping timeout: 246 seconds)
[20:11:34] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has quit (Ping timeout: 240 seconds)
[20:14:51] brfransen (brfransen!~brfransen@71.11.51.80) has joined #mythtv
[20:18:34] cbovy (cbovy!~cbovy@2001:470:1f15:ff2:39b8:2094:fdc6:79dd) has quit (Quit: Leaving)
[20:47:51] amessina (amessina!~amessina@unaffiliated/amessina) has joined #mythtv
[20:54:49] Jordack (Jordack!~Jordack@75-151-31-172-Michigan.hfc.comcastbusiness.net) has quit ()
[20:57:07] coling (coling!~colin@cpc8-sgyl36-2-0-cust443.18-2.cable.virginm.net) has joined #mythtv
[21:00:27] SteveGoodey (SteveGoodey!~steve@host5-81-230-128.range5-81.btcentralplus.com) has quit (Quit: Konversation terminated!)
[21:00:52] Steve-Goodey (Steve-Goodey!~steve@host5-81-230-128.range5-81.btcentralplus.com) has quit (Quit: Konversation terminated!)
[21:21:10] willcooke (willcooke!~willcooke@ubuntu/member/willcooke) has quit (Quit: Do your hobbies)
[21:55:21] stuartm: easier just to handle the CSRF, read in the token from the session cookie and send it back with the request
[22:05:12] stuartm: assuming the initial requests are changed to GET
[22:05:29] stuartm: and just the submit is POST
[22:27:35] Tobbe5178 (Tobbe5178!~asdf@h55n9-sv-a13.ias.bredband.telia.com) has quit (Read error: Connection reset by peer)
[22:28:01] Roklobotomy (Roklobotomy!~Dirkka@ppp118-209-128-112.lns20.mel8.internode.on.net) has joined #mythtv

IRC Logs collected by BeirdoBot.
Please use the above link to report any bugs.