Username
Password
Login is SSL protected. By clicking on "Log in Now" you agree to gixen.com terms of usage.


   SearchSearch     

Gixen login possible with 2 passwords

 
Post new topic   Reply to topic    Gixen.com Forum Index -> Support
View previous topic :: View next topic  
Author Message
nirmalts
Guest





PostPosted: Thu Aug 20, 2009 12:02 pm    Post subject: Gixen login possible with 2 passwords Reply with quote

Sorry if this question is already addressed in the forum. I did a search, but couldn't find the right answer.

I changed my ebay password recently and have been using Gixen successfully for a while since then. Today I accidently logged into Gixen with my old ebay password and it worked (but shows my snips as empty). Although this doesnt cause me any problem because I would use my current password for snips, it still makes me wonder why this Gixen behaviour. Has anyone else noticed this before.?

Thanks and regards
Back to top
juangrande



Joined: 09 Aug 2007
Posts: 890
Location: San Diego, California, USA

PostPosted: Thu Aug 20, 2009 2:38 pm    Post subject: Reply with quote

Your Gixen credentials are stored as the pair (username, password). This means that if you "log in" to Gixen with the same username but a different password, Gixen will treat you as a different user. That is why your snipes didn't show when you "logged in" with your old password.

Even though you "logged in" to Gixen with your old password, any snipes you scheduled with Gixen using your old password would fail because Gixen would be unable to log in to eBay with your old password and thus would be unable to place your bids.
_________________
John

If you don't know where you are going, you will wind up somewhere else.
--- Yogi Berra
Back to top
View user's profile Send private message
Cupid



Joined: 09 Aug 2007
Posts: 6874
Location: Bristol, UK

PostPosted: Thu Aug 20, 2009 4:51 pm    Post subject: Reply with quote

Hmm interesting,

This might explain why some people have been finding that they log in and all their snipes have dissappeared.

You shouldn't be able to log into Gixen with a different password than was sucessfully used previously that cant also be used to log into eBay, this should be the case with an old password once you have sucessfully logged into Gixen with your new password for the first time... Gixen should only store one hash of the password to check against, and that should be from the last sucessful log in to eBay... So I can understand why people can log in to Gixen with their old password when they have just changed their eBay password (and have not successfully logged into gixen since doing so) because Gixen stores a hash and then if it is the same as the one generated from logging in again it doesnt check back with eBay, fair enough... but if there is not a match it should check again with eBay shouldn't it?... and I think that is where the problem must lie.

You shouldn't be able to log into Gixen with two different passwords, and then keep swapping back a forth between them (without also changing your eBay password), because Gixen should be checking with eBay each time you change the credentials that you use here.
_________________
Mark
Back to top
View user's profile Send private message
mario
Site Admin


Joined: 03 Oct 2006
Posts: 6819

PostPosted: Thu Aug 20, 2009 6:20 pm    Post subject: Reply with quote

This is all correct Mark, well explained. However I don't think the problem of some users logging in and seeing empty snipe list is related to password hash... The very first time you log in with your new password, this hash is replaced... and you shouldn't be able to log in with the old password ever again.
Back to top
View user's profile Send private message Send e-mail
Gixen
Advertisements





PostPosted: Thu Aug 20, 2009 6:20 pm    Post subject:

Back to top
juangrande



Joined: 09 Aug 2007
Posts: 890
Location: San Diego, California, USA

PostPosted: Thu Aug 20, 2009 8:16 pm    Post subject: Reply with quote

OK, so I see that my explanation was not accurate. I should have just let Mark and Mario answer this. This reminds me of the Chinese proverb: "It is better to be silent and thought a fool than to open one's mouth and remove all doubt." Very Happy

This raises a question: under what circumstances does Gixen actually check that it can successfully log in to eBay? After all, the only time this problem could occur is when Gixen does not check the user's eBay credentials.
_________________
John

If you don't know where you are going, you will wind up somewhere else.
--- Yogi Berra
Back to top
View user's profile Send private message
nirmalts
Guest





PostPosted: Thu Aug 20, 2009 8:43 pm    Post subject: Reply with quote

Thanks guys for your replies.

Just now I noticed that I can log into Gixen with my username and "any" password. Needn't be my old or new.

I missed a snip once in this way. I thought I had logged in successfully and added a snipe with a wrong password (before adding the new snip, my snip list was empty anyway. So I didnt realise that I had logged in wrongly to Gixen). In the end Gixen could not snip because it couldn't log into ebay with the wrong password.

Is this behaviour expected?
Back to top
Cupid



Joined: 09 Aug 2007
Posts: 6874
Location: Bristol, UK

PostPosted: Fri Aug 21, 2009 1:56 am    Post subject: Reply with quote

John,

I dont think your explanation was inaccurate, I just dont think it pinpointed the problem, yet, though it moved the discussion forward in a positive way, as always... but then nor did I, it seems... I was also trying to do so though.

I think you (in your second response) and nirmalts have actually explained it best, I think there is a problem with Gixen verifying the credentials with eBay in the circumstances where it should... that is the point I was trying to get to, but wasnt successful.

nirmalts,

In answer to your final question, no it is not expected, I think you have pinpointed the problem.
_________________
Mark


Last edited by Cupid on Fri Aug 21, 2009 6:07 am; edited 1 time in total
Back to top
View user's profile Send private message
mario
Site Admin


Joined: 03 Oct 2006
Posts: 6819

PostPosted: Fri Aug 21, 2009 5:43 am    Post subject: Reply with quote

nirmalts wrote:
Just now I noticed that I can log into Gixen with my username and "any" password. Needn't be my old or new.


Well that's it. When making recent changes I removed an important piece of code that actually allows you to do that. As users' snipes are tied to pair (username, password) this explains why some users would also get an empty list (they mistyped their password). This is fixed now.

Many people will be upset about this (whoever mistyped their password when logging in), rightfully so - I messed up this time.
Back to top
View user's profile Send private message Send e-mail
Cupid



Joined: 09 Aug 2007
Posts: 6874
Location: Bristol, UK

PostPosted: Fri Aug 21, 2009 6:19 am    Post subject: Reply with quote

Thanks for fixing it again Mario... hopefully that should reduce the number of support queries we were getting at the moment... fantastic work, as usual, and as we have come to expect... you mustn't start thinking we are taking you for granted though.. we do appreciate the work that you put into this.
_________________
Mark


Last edited by Cupid on Fri Aug 21, 2009 7:32 am; edited 1 time in total
Back to top
View user's profile Send private message
mario
Site Admin


Joined: 03 Oct 2006
Posts: 6819

PostPosted: Fri Aug 21, 2009 6:49 am    Post subject: Reply with quote

On a bright side though - the main server is migrated to a much stronger platform now (it was about time), and encoding issues in usernames / passwords (remember all the problems with special characters) are fixed for good.
Back to top
View user's profile Send private message Send e-mail
juangrande



Joined: 09 Aug 2007
Posts: 890
Location: San Diego, California, USA

PostPosted: Fri Aug 21, 2009 7:43 am    Post subject: Reply with quote

mario wrote:
On a bright side though - the main server is migrated to a much stronger platform now (it was about time), and encoding issues in usernames / passwords (remember all the problems with special characters) are fixed for good.


That is a very bright side, Mario! Thank you!! I never could remember which special characters caused problems and now I don't have to. Very Happy
_________________
John

If you don't know where you are going, you will wind up somewhere else.
--- Yogi Berra
Back to top
View user's profile Send private message
Cupid



Joined: 09 Aug 2007
Posts: 6874
Location: Bristol, UK

PostPosted: Fri Aug 21, 2009 9:35 am    Post subject: Reply with quote

Yes, I agree, that was a pain for quite a few users, a great improvement for all those that were affected by it, including, of course, those of us that keep an eye on these boards and try to help out users where we can.
_________________
Mark
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Gixen.com Forum Index -> Support All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

© 2019 Gixen.com. Forum powered by phpBB © 2001, 2005 phpBB Group.