On Wed, Jun 28, 2006, Martin Konold wrote:

> the OpenPKG registration process is still a big annoyance and hindering
> adoption/usage of OpenPKG a lot.
>
> E.g. the stupid registration feature requires email validation within a short
> period of time (some minutes).

No, the registration timeout is 1 hour(!), not a few minutes. And it was
set to this value last time in April when you complained the first time ;-)

> This breaks much too often! Think about people
> doing something else in the meantime and especially consider the very commin
> smtp greylisting.

One hour should be good enough even for greylisting. But ok, I've
increased it now to 8 hours. But please keep in mind that both the
timeout and the blocking of additional enrollments before the timeout
runs out are important: the blocking exists to make sure that the
enrollment process cannot be abused for spamming purposes by just
creating enrollments too often within a short timeframe. OTOH, if the
timeframe is too large this becomes a problem if the mail with the
activation URL is lost somewhere (spam filters!) as a new enrollment is
then blocked until the timeout runs out. So, sorry, we cannot get rid of
the timeout and we cannot increase it too much.

> An additional idiocy is that after the registration timed out the system
> dissallows to start over :-((
>
> https://registry.openpkg.org/ase
>
> "Email address already in use since 2006-06-28 20:39:26"

According to the OSSP ase code this particular error really means what
it says: that the Email is already in _use_, i.e., it was already
successfully(!) enrolled. This error does _not_ occur if the timeout
happened. The error on timeouts is "Email address already in use for
enrolling since ....". This is the "blocking" case I mentioned above to
prevent abuse by spammers.

> This is now the third time that I tried to register and the system is still
> not working reasonably.
> [...]

Sorry that it still is not as good as it could be. It is rather
complicated to balance between abuse prevention and good user
acceptance. But as I tried to explain above, the enrollment timeouts
exist for good reasons. Sorry that they bothered you. But according to
the database you now at least registered successfully under the address
[EMAIL PROTECTED] Sorry for the inconveniences.

                                       Ralf S. Engelschall
                                       [EMAIL PROTECTED]
                                       www.engelschall.com

______________________________________________________________________
The OpenPKG Project                                    www.openpkg.org
User Communication List                      [email protected]

Reply via email to