Posts

Custom Login Validation

One of the many behaviors that I was asked recently to create was to allowing hide/show of the password and warn users that the locked character key is active. Since this solution could get complex and I just wanted to create a quick/simple demo and because of that I'm going to pick jquery. I could late come back and do it in another library but I already have a few ideas what I want to do.

Notes:
input - Is it standard practice to indicate on the form that Caps Lock is on? - User Experience Stack Exchangehtml5 - What's the difference between HTML 'hidden' and 'aria-hidden' attributes? - Stack Overflow
Examples: 

Edit fiddle - JSFiddleBetter Passwords #3: Caps-lock Warnings — SitePointCode Bins : Password masking in jQuery

AspnetCore Oauth Active Directory

I'll be honest active directory has always been a difficult area for me to develop in. Which is why I prefer a basic user authorization that's just attached to the database. What I'm trying to do is leverage Oauth and inside pass in credentials to the active directory. Thous prevent users with the built in prompt and instead handle the authorization just like you would if it was inside an aspnet core Identity table. However this is no table! This means they can pass me any username and password. Not just what they are logged as under the domain (and under their browser). Very simple just difficult to explain with all the major buzz words floating around like Single Sign On, external service providers and etc. Which where I start to have trouble explain because I like to keep things simple. What my application will do is have an authorization page and redirect users to it if that are not logged in. Once I figure out they are who they say they are with the AD then continue …

Nginx with Naked Domains

This right I'm going naked on everything! Non-www and everything lowercase. Just to simplify my urls. If you couldn't write it out naturally or if it takes too long then I avoid making it a path. Special cases like unique guid url parameters being the exception. For the sites that have a ton parameters this its understandable but for the domains this rule really should be applied. In some cases might say the path is up to the application however if the framework doesn't handle this is a fall back.

https://superuser.com/questions/432674/nginx-remove-www-from-httpshttps://www.digitalocean.com/community/tutorials/how-to-redirect-www-to-non-www-with-nginx-on-ubuntu-14-04http://nginx.org/en/docs/http/server_names.html

Orchard 1.10.1 - Seo & Social Module

Most of the work I do for orchard is open source, this is because nothing other than content is property of my employer. Even if open source makes some employers uncomfortable a lot of my work is about success of a given project or the development process flow. In other words is everyone able to achieve what with the development or features created within a given project. That's just my take on things, I'm sure someone will disagree, putting security in a much higher priority. Which I think is a big part of my reason for being open source on the things I could improve unpon.

Notes:

https://stackoverflow.com/questions/11149157/orchard-getting-the-contents-title-from-the-theme-layouthttps://stackoverflow.com/questions/11688626/orchard-theme-placement-not-overriding-module-placementhttps://stackoverflow.com/questions/13000711/add-individual-page-titles-to-html-document-head-in-orchard-cmshttps://stackoverflow.com/questions/17737509/orchard-cms-custom-theme-every-page-displaying-ti…

Content Security Policy & Best Practices

Image
This article is mostly on configuration with nginx and maybe a little on IIS.



Notes:
https://developer.mozilla.org/en-US/docs/Web/HTTP/CSPhttps://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestorshttps://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestorshttps://csp-evaluator.withgoogle.comhttps://securityheaders.io/

Nginx Best Practices Extended

Bootstrap Cheatsheet

There are many things I wouldn't call myself a master of but bootstrap is one of them. I never seem to have difficultly with css but do forget a few things cause they aren't really all that important! Haha css joke...

https://stackoverflow.com/questions/11425115/css-media-queries-for-pixel-density-moz-min-device-pixel-ratio-vs-min-moz-dehttps://stackoverflow.com/questions/23700941/bootstrap-full-responsive-navbar-with-logo-or-brand-name-texthttps://stackoverflow.com/questions/8805208/css-min-width-and-max-width-and-flexible-layout
Positions

Learn CSS Positioning in Ten Steps: position static relative absolute floatCSS z-index propertyCSS PositioningFree responsive html5 CSS website templates, create your own free websiteHow to Center Anything with CSS50+ Nice Clean CSS Tab-Based Navigation ScriptsTable centering using CSS or HTML: theodorakis.netHTML5 Simplequiz 6: Zeldman’s fat footer | HTML5 Doctor CSSTidy
https://css-tricks.com/multiple-class-id-selectors/opacityparam tag Miscel…