Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1
  • 2

TOPIC: Bypassing the authentication of Lime Survey

Bypassing the authentication of Lime Survey 1 year 6 months ago #92973

  • JVG
  • JVG's Avatar
  • OFFLINE
  • Fresh Lemon
  • Posts: 7
  • Karma: 0
Hi,

We are developing an app based on CI and integrating it with lime survey.
The requirement is that when admin logs in into our app and clicks onto the survey link he should be redirected to the admin panel. But the problem we are facing is bypassing the limesurvey authentication.

We have tried with delegating authentication to webserver but we are unable to do so. I've gone through the instructions of optional seetings and implemented it too..But it throws an error with invalid username/password when authWebServer is set to true..i am unable to track the problem or is there something to do with enabling authentication at the web server?

So we request you to suggest a wayout for this.
The administrator has disabled public write access.

Bypassing the authentication of Lime Survey 1 year 6 months ago #92976

  • Ben_V
  • Ben_V's Avatar
  • OFFLINE
  • Platinum Lime
  • Posts: 1081
  • Thank you received: 240
  • Karma: 76
You can copy the login form in an external file, setting user & password default values.
Use JQuery for submit button emulation.

To help you to find a way, I attach 2 html samples (depend on your LS version):
Just adapt:
YOURDOMAIN
USERNAME
PASSWORD

No need to upload; can work from your desktop if the 'action' url value is correct...

If you have to use some differents sets admin+password, just change it for php file and set variables.

File Attachment:

File Name: skip_auth.zip
File Size: 3 KB
Benoît

goo.gl/Bw5iM => Recherche GG dans le forum français (remplacer "exemple" dans la barre de recherche)
goo.gl/WX8PH => GG search for english forum (Replace "example" in the search bar)
goo.gl/IxiGu => Búsqueda en el foro en español (Cambiar "ejemplo" en la barra de...
The administrator has disabled public write access.
The following user(s) said Thank You: JVG

Bypassing the authentication of Lime Survey 1 year 6 months ago #92978

  • DenisChenu
  • DenisChenu's Avatar
  • OFFLINE
  • Moderator Lime
  • Posts: 6334
  • Thank you received: 818
  • Karma: 243
JVG wrote:
We have tried with delegating authentication to webserver but we are unable to do so. I've gone through the instructions of optional seetings and implemented it too..But it throws an error with invalid username/password when authWebServer is set to true..i am unable to track the problem or is there something to do with enabling authentication at the web server?
What is your version ?

There are some patch for authWebServer in the last version.

Denis
The administrator has disabled public write access.

Bypassing the authentication of Lime Survey 1 year 6 months ago #92980

  • JVG
  • JVG's Avatar
  • OFFLINE
  • Fresh Lemon
  • Posts: 7
  • Karma: 0
I am using 2.0 version. Can u please attach the link for the patch. Does it bypass LimeSurvey authentication?
The administrator has disabled public write access.

Bypassing the authentication of Lime Survey 1 year 6 months ago #92981

  • DenisChenu
  • DenisChenu's Avatar
  • OFFLINE
  • Moderator Lime
  • Posts: 6334
  • Thank you received: 818
  • Karma: 243
JVG wrote:
I am using 2.0 version.
Buils number ?
Can u please attach the link for the patch. Does it bypass LimeSurvey authentication?
LS oficial core last build number : github.com/LimeSurvey/LimeSurvey
The administrator has disabled public write access.

Bypassing the authentication of Lime Survey 1 year 6 months ago #92983

  • JVG
  • JVG's Avatar
  • OFFLINE
  • Fresh Lemon
  • Posts: 7
  • Karma: 0
I am using LS with build number is 130206.Will my problem be solved if i replace it with above build?
The administrator has disabled public write access.

Bypassing the authentication of Lime Survey 1 year 6 months ago #92995

  • JVG
  • JVG's Avatar
  • OFFLINE
  • Fresh Lemon
  • Posts: 7
  • Karma: 0
I tried installing the latest build that you suggested but still there is a problem. What I need is when I login through my app and when I click on the link 'Add survey' it should bypass LimeSurvey authentication and show me the admin panel directly.

I installed the new build and reset the authWebserver variable to 'true' and edited the admin name from 'lime_users' table to the same name as is in my app login for admin. When I was done with al these changes and clicked on link 'Add survey' it redirects to this page
http://localhost/LimeSurvey-master/index.php/admin/authentication/sa/login with error Invalid username/password

Please help me through this.

Thank you
The administrator has disabled public write access.

Bypassing the authentication of Lime Survey 1 year 6 months ago #93007

  • DenisChenu
  • DenisChenu's Avatar
  • OFFLINE
  • Moderator Lime
  • Posts: 6334
  • Thank you received: 818
  • Karma: 243
Never used autWebServer,

Can you set debug to 2 and fill a bug report ?

Denis
www.limesurvey.org/en/community-services/bug-tracker
The administrator has disabled public write access.

Bypassing the authentication of Lime Survey 1 year 6 months ago #93009

  • JVG
  • JVG's Avatar
  • OFFLINE
  • Fresh Lemon
  • Posts: 7
  • Karma: 0
I didnt get u? what is debug to 2?

Yes, will fill a bug report

Thank You.
The administrator has disabled public write access.

Bypassing the authentication of Lime Survey 1 year 6 months ago #93020

  • JVG
  • JVG's Avatar
  • OFFLINE
  • Fresh Lemon
  • Posts: 7
  • Karma: 0
Ben_V Wrote:
To help you to find a way, I attach 2 html samples (depend on your LS version):
Just adapt:
YOURDOMAIN
USERNAME
PASSWORD



Thank You so much. I tried with the script and its working!!! :)
Last Edit: 1 year 6 months ago by JVG. Reason: forgot to add few lines
The administrator has disabled public write access.
  • Page:
  • 1
  • 2
Moderators: ITEd
Time to create page: 0.130 seconds
Donation Image