On Sun November 9 2008, Chris Nolan wrote:
I'd also be happy to help host/setup a blog for rpmfusion. I have
good
experience with wordpress - PHP is more my realm than packaging!
If FAS allows some kind of API for login/group verification then I'm
fairly confident I can hack together a wordpress plugin that uses this
to authenticate users.
Anyone else have thoughts on this?
With using the FAS credentials, that allow to produce major damage in the
wrong hands, within an application that is considered not very secure make my
security concerns grow a lot more. I know that they are already used for
OpenID and Mediawiki in Fedora, so there are a lot of attack vectors there,
but maybe RPMFusion could be more secure.
Regards,
Till