You are not logged in.

#1 2012-02-23 21:22:16

Alir3z4
Member
From: مغز
Registered: 2010-11-06
Posts: 14
Website

An idea for rewriting AUR web-interface

Hi
I just checkout the aur.git, and i guess it's better to rewrite it in other technologies for better maintaining/features/bug-fixing and implementing other enhancement.
For example nowadays web-applications shoulda be totally safe against XSS/CRSF, but couple of days ago aur experienced some XSS vulnerabilities, and so on..
I'm not talking about the code or code styling or something no, those are fine. But something like php without any framework help, is totally disaster. also i'm not talking about using php-framework either
If any plan is on, i really like to know about it.
So what do you think ?

Last edited by Alir3z4 (2012-02-23 21:23:30)

Offline

#2 2012-02-23 21:29:09

Awebb
Member
Registered: 2010-05-06
Posts: 6,352

Re: An idea for rewriting AUR web-interface

I don't see you hackin' like there's no tomorrow 8)

Offline

#3 2012-02-23 23:02:48

falconindy
Developer
From: New York, USA
Registered: 2009-10-22
Posts: 4,111
Website

Re: An idea for rewriting AUR web-interface

Alir3z4 wrote:

Hi
I just checkout the aur.git, and i guess it's better to rewrite it in other technologies for better maintaining/features/bug-fixing and implementing other enhancement.
For example nowadays web-applications shoulda be totally safe against XSS/CRSF, but couple of days ago aur experienced some XSS vulnerabilities, and so on..
I'm not talking about the code or code styling or something no, those are fine. But something like php without any framework help, is totally disaster. also i'm not talking about using php-framework either
If any plan is on, i really like to know about it.
So what do you think ?

"Should" be safe and "are" safe are extremely different. Tools like burpsuite and skipfish exist simply because csrf and xss vulnerabilities will always sneak in regardless of the framework you use. I suspect that you would be surprised at how many sites out there have numerous vulnerabilities. In particular, I'll point out that despite things like PCI compliance, banks are notorious for being years behind in terms of security.

Regardless, rewriting the aur comes up pretty often. Sadly, I can't liken it to duke nukem forever anymore, bit hopefully you get the point. I encourage you to prove me wrong...

Offline

#4 2012-02-23 23:16:30

Alir3z4
Member
From: مغز
Registered: 2010-11-06
Posts: 14
Website

Re: An idea for rewriting AUR web-interface

Security was just an example :D,  and yes of course there is many web-sites have numerous vulnerabilities. But you can't take as "other are insecure why not aur"
As i said, XSS vulnerabilities is just an instance, my whole point is, there are another ways to develop/maintain aur. *of course there are pretty often ways to maintain archlinux itself - Maybe you gonna say!

Last edited by Alir3z4 (2012-02-23 23:18:47)

Offline

#5 2012-02-24 00:54:57

keenerd
Package Maintainer (PM)
Registered: 2007-02-22
Posts: 647
Website

Re: An idea for rewriting AUR web-interface

I've been working on an AUR rewrite, http://aur3.org  It has some of the stuff you mention, such as no PHP.  Progress has slowed quite a bit lately, but it has been a good mirror when the real AUR is down for repairs.

Offline

#6 2012-02-25 13:37:25

Alir3z4
Member
From: مغز
Registered: 2010-11-06
Posts: 14
Website

Re: An idea for rewriting AUR web-interface

Is that because of the KISS ? or folks really dont't give a heck about it ?
What about full-text search?

Offline

#7 2012-02-25 16:43:11

Allan
Pacman
From: Brisbane, AU
Registered: 2007-06-09
Posts: 11,416
Website

Re: An idea for rewriting AUR web-interface

There were also lots of AUR2 attempts that all died out.   The reason is generally lack of motivation to rewrite something that basically works.

Offline

#8 2012-02-25 16:54:13

Alir3z4
Member
From: مغز
Registered: 2010-11-06
Posts: 14
Website

Re: An idea for rewriting AUR web-interface

Allan wrote:

There were also lots of AUR2 attempts that all died out.

Ow i didn't know there were AUR2 also :|
The main reason about "died-out" is no body shows any interest, at the first place ppl came and say what? who? ha? go-away!, why you want ruin something that works great

Offline

#9 2012-02-25 17:04:30

karol
Archivist
Registered: 2009-05-06
Posts: 25,440

Re: An idea for rewriting AUR web-interface

Offline

#10 2012-02-26 12:58:29

Alir3z4
Member
From: مغز
Registered: 2010-11-06
Posts: 14
Website

Re: An idea for rewriting AUR web-interface

karol wrote:

Did you found aur's current devs come into and even say hi?, most of them are just normal user who want something ?
Seems shoulda bring other aur implementation on wheelchair with this hope may someday by accident current aur get into some trouble and .... !

Last edited by Alir3z4 (2012-02-26 13:07:58)

Offline

#11 2012-02-26 13:08:40

karol
Archivist
Registered: 2009-05-06
Posts: 25,440

Re: An idea for rewriting AUR web-interface

The current AUR sort of works (but lacks many 'nice to have' features), AFAIK the other implementations didn't get far. If you show us a working AUR-ng, we can simply copy the PKGBUILDs (not sure about the comments) there.
I don't think we need approval from whoever keeps AUR up and running.


Edit: Obviously you might have to convince TUs to start patrolling AUR-ng instead of the old AUR in case of AUR v. AUR-ng competition.

Last edited by karol (2012-02-26 13:14:02)

Offline

Board footer

Powered by FluxBB