Saturn  Forum - Saturn Enthusiasts Forums

Saturn Forum - Saturn Enthusiasts Forums (https://www.saturnforum.com/forum/)
-   Saturn Astra (https://www.saturnforum.com/forum/saturn-astra-32/)
-   -   Saturn Astra manual transmission fluid change tips (https://www.saturnforum.com/forum/saturn-astra-32/saturn-astra-manual-transmission-fluid-change-tips-13817/)

AstraFasta2 Jun 26, 2025 05:14 PM

Saturn Astra manual transmission fluid change tips
 
2 Attachment(s)
The forum does not seem to link these old archive posts correctly. I think it is killing the session token s=.

I have included the archive.org link in txt file below until I can figure out how to make these links work.

Just copy the full link and paste it into your broswer, hit enter.

AstraFasta2 Jun 26, 2025 11:22 PM

I know what is happening. This forum's software is editing the full link I pasted in. I couldn't figure how to prevent that action, so I put the full working link in a txt file in the first post.

derf Jun 27, 2025 12:47 AM

That's pretty whack.
I tried some underhanded stuff but none of it worked.

it just throws out the session info. Must not recognize the flag. Maybe it's been updated to something else in the newer versions of ....... stuff.
I even went back in and pasted it back into the source code for the post and it still threw it out on save.

derf Jun 27, 2025 01:20 AM

Here we go.

------
Deleting session ID information from URLs in Internet Brands forum software
Deleting session ID information from URLs in Internet Brands forum software, or any web application for that matter, is a security best practice because passing session IDs in the URL can lead to session hijacking and other security risks
. The recommended way to manage sessions is by using secure cookies.
Here's a breakdown of why this is important and how it relates to general web security best practices:

Why Avoid Session IDs in URLs?
  • Security Risks: Sharing session IDs in URLs makes them vulnerable to interception through various methods like packet sniffing or simply being copied and shared, which can lead to session hijacking.
  • Leakage through Referer Headers: When a user clicks on a link with a session ID in the URL, that information can be included in the Referer header, potentially exposing the session ID to the linked website.
  • Browser History: Session IDs in URLs can be stored in browser history, increasing the risk of unauthorized access if someone gains access to the user's browser.
  • Server Logs: Server logs can capture URLs, including those with session IDs, creating a potential security vulnerability if these logs are not properly secured.
  • Session Fixation: An attacker can send a user a crafted URL with a known session ID. If the user logs in, the attacker can then use that session ID to gain access to the account.
oh well

AstraFasta2 Jun 27, 2025 01:37 AM

I didn't realize those session IDs were potential security risks. Will have to think about how those are archived and accessed going forward. The wayback machine is a great idea but a mess in practice.

derf Jun 27, 2025 01:25 PM

Well, Chrome lets them through from the address bar.
So I suppose we just have to figure out how to have the link use google as the link processor, not the local SW.
Maybe appending a window=blank onto the end? Or whatever that is code wise.

derf Jun 27, 2025 01:35 PM

Storing Info on Saturnforum -- References to info on other forums
 
I've always thought the following but have never expressed it:

I would like our forum to have as much content pasted into it as possible so that we avoid the pitfalls of the Saturnfans debacle.
I realize this is not always practical, and often we want to refer to an entire thread somewhere else, not just a single post.
I have violated my own wishes more than anyone.

Maybe we could copy in the most relevant post of a thread AND include the link to the entire thread?
Then the most useful info is captured here and the user that wants to dig deeper can view the entire thread.

With Saturnfans gone and Sixthsphere pretty much living on Facebook, we are one of the few websites left dedicated to Saturn technical issues.
I'm aware there is a subreddit on Reddit; I'm yet to investigate.

Feedback welcome.


All times are GMT -5. The time now is 05:06 AM.


© 2026 MH Sub I, LLC dba Internet Brands