Google Web Accelerator & Olympus

Discussion of general topics related to the new version and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Forum rules
Discussion of general topics related to the new release and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
expert01
Registered User
Posts: 45
Joined: Thu Jul 22, 2004 9:04 pm

Google Web Accelerator & Olympus

Post by expert01 »

I've noticed Olympus has some new features over the 2.x version of phpBB. Do these features prevent the Google Web Accelerator bug (of users accessing pages only other users can see)? Has anyone tested?

DeadEye686
Registered User
Posts: 448
Joined: Mon Jul 21, 2003 7:18 pm
Contact:

Re: Google Web Accelerator & Olympus

Post by DeadEye686 »

expert01 wrote: I've noticed Olympus has some new features over the 2.x version of phpBB. Do these features prevent the Google Web Accelerator bug (of users accessing pages only other users can see)? Has anyone tested?
To my knowledge, there's absolutely nothing that can prevent this bug except for Google fixing it.

Edit: Let me give my reasoning for that, so that someone can correct me if I'm incorrect. The problem currently is that if GoogleWA finds a cached version of the "private" page on its servers (it's actually more complicated than this, as there are a couple of algorithms to determine whether this happens - these algorithms need major tweaking at the moment), then it simply doesn't even contact the server with phpBB, it just serves the user the page found in its cache. Therefore, short of not providing the private page to an authenticated user (and thusly passing it into the GoogleWA cache if the user is using it), there is nothing that phpBB could do to prevent it.

expert01
Registered User
Posts: 45
Joined: Thu Jul 22, 2004 9:04 pm

Re: Google Web Accelerator & Olympus

Post by expert01 »

Does having the ?sid= change the pages so they're not cached?

User avatar
A_Jelly_Doughnut
Registered User
Posts: 1780
Joined: Wed Jun 04, 2003 4:23 pm

Re: Google Web Accelerator & Olympus

Post by A_Jelly_Doughnut »

Google does indeed cache Olympus's pages, even with the SID. I'm not sure that it is a big deal with phpBB, though, from what I've read on Accelerator. phpBB uses real confirm options, not javascript.
A_Jelly_Doughnut

expert01
Registered User
Posts: 45
Joined: Thu Jul 22, 2004 9:04 pm

Re: Google Web Accelerator & Olympus

Post by expert01 »

I meant will it change so that when you go to an Olympus forum the ?sid= is different for you and you won't see stuff you're not supposed to.

nezermundy
Registered User
Posts: 11
Joined: Tue Jul 20, 2004 8:05 pm

Re: Google Web Accelerator & Olympus

Post by nezermundy »

The porblem is Google could automaticly log you into the site as some one else, even an admin!

User avatar
the_dan
Registered User
Posts: 700
Joined: Thu Apr 01, 2004 7:36 pm

Re: Google Web Accelerator & Olympus

Post by the_dan »

nezermundy wrote: The porblem is Google could automaticly log you into the site as some one else, even an admin!
It won't log you in - You just mioght be able to view sections of it. You can't make any changes etc.

Cap'n Refsmmat
Registered User
Posts: 219
Joined: Tue Jan 25, 2005 11:31 pm

Re: Google Web Accelerator & Olympus

Post by Cap'n Refsmmat »

I've heard of people being able to read other people's PMs with it.

User avatar
psoTFX
Registered User
Posts: 1984
Joined: Tue Jul 03, 2001 8:50 pm
Contact:

Re: Google Web Accelerator & Olympus

Post by psoTFX »

Indeed, quite possible ... but you'll get nowhere if you try and POST anything via a cached page. At that stage it'll require you to reauthenticate as appropriate.

User avatar
stubbers
Registered User
Posts: 406
Joined: Sat Oct 23, 2004 10:36 pm
Location: LoSt
Contact:

Re: Google Web Accelerator & Olympus

Post by stubbers »

So wait, google can cache restricted sub-forums, can't you lock google out using permissions

Post Reply