Skip to: Site menu | Main content

michael's blog

Drupalcon Boston: Day 3

Drupal Security - Best Practices and Process Discussion

Greg Knaddison and James Walker, both on the Drupal security team, presided over this session.

They talked about the various attack vectors that hackers utilize:
  • authentication
  • authorization
  • client-side attacks (XSS and cross site request forgery [CSRF]
  • information disclosure

They stressed the idea of being a secure user by using a strong password, avoiding unecrypted WiFi and FTP (opting for ssh/keys instead), and being really, really careful with UID 1. On the server side, using SSL for login pages (via the Secure Pages module) if desireable, if possible.

Submitted by michael on Wed, 03/05/2008 - 9:29pm
Filed under:

Drupalcon Boston: Day 2

Here's a brief rundown of the sessions I attended today. Case Study

This site recently re-launched in a massive way - the entire site (as well as a companion site) was re-written in Drupal with social networking at it's core. It launched with more than 500,000 nodes that were imported from a previous content management system.

One of their goals was that they wanted users to find each other from common ideas, not common resumes. Facilite new relationships - not existing ones.

During the design phase, about 200 professionally wireframes were created. Lullabot and Achieve Internet did a lot of the heavy lifting for the site's functionality while Tree House Interactive did the themeing.
Submitted by michael on Tue, 03/04/2008 - 9:36pm
Filed under:

Drupalcon Boston: Day 1

I'm in Boston for the 2008 edition of the Drupal lovefest (U.S. edition), and holy cow what a difference a year makes. I arrived just as Dries was taking the stage for his State of the Drupal keynote, and I was amazed at the size of the crowd. I knew that the conference had sold out (800 attendees), but I was shocked at the sheer visual spectacle of the size of the crowd compared to the 2007 Drupalcon in Sunnyvale, CA. Jusy about everything about Drupalcon Boston is big; the crowd, the venue, the session rooms. The only thing that isn't big: the food court at the convention center. Yikes.

Submitted by michael on Mon, 03/03/2008 - 10:34pm
Filed under:

Creating Modal "Please Wait..." Dialog Boxes with jqModal jQuery Plugin

Part of the power of having jQuery integrated with Drupal is the ability to take advantage of the strong jQuery developer community. There are many, many plug-ins for jQuery that can add some great functionality to your site - usually with very little code.

jqModal is just one of these plug-ins. It can be used to create modal (or non-modal) dialog boxes. In this example, I'm going to show you how to use it to create a modal "Please Wait..." dialog box. This can be useful when your user submits a form that might take a few seconds to process. Having a modal dialog box not only gives the user some feedback that the site is actually doing something, but it also stops the user from clicking the "submit" button multiple times.
Submitted by michael on Sun, 02/24/2008 - 12:06pm
Filed under:

Case Study: Increasing YSlow Score 30+ Points in Less Than One Hour

Ever since a client of mine asked me to look into the Firebug add-on YSlow, I've been interested in using it to increase performance on my Drupal (version 5) web sites. Wim Leer's recent posting about improving Drupal performance inspired me to take action to see what kind of improvements I could make.

Before I get into the details, please don't confuse me with an Apache guru. I know enough to modify various settings in an httpd.conf or an .htaccess file, but only after I've done my due diligence to make sure I'm not going to irrevocably screw things up.

Submitted by michael on Wed, 02/06/2008 - 3:19pm
Filed under: