Thanks! Currently, we're attempting to implement CSP (Content Security Policy) to prevent inline javascript from running, so we're hopeful this will solve our issue.
Hello,
Recently, we have had a few people attempt to XSS our site to prevent usage, and what is happening is they are running scripts on our site with script tags that are being inputted in the Registration page. We've been trying to figure out how we can escape or sanitize these inputs to essentially remove the scripts tag(s), so the code won't run.
Any ideas or thoughts would be greatly appreciated!
Good morning,
I am hoping someone can help me with an issue I have. My issues is that a flight will duplicate it self on the live flight map inside the crew center. I’ve attcahed a image of what I’m exactly talking about. All of the “Live Flights” shown, are the excat same, I’ve just redacted a user’s name.
Image
Good evening pilots,
JetBlue Virtual is pleased to announce 'A Night in NYC.' A Night in NYC is a VATSIM event put on by JetBlue Virtual on March 16, 2019, at 2100Z-2330Z. If you are interested in joining us, you can make your account here: https://crew.flyjetbluevirtual.org/index.php/registration & Sign-Up here: https://flyjetbluevirtual.org/index.php/events
UPDATE: I was able to get the Live Map on my site, the only issue is that when you go to it, you have to be logged in, or it doesn't show, and when you login, it lets you browse the whole site, as I had attempted it through iframe. Any ideas on how to prevent this?
Hi,
I am trying to get a live flight map on another website, that is outside the folder phpvms is in. So, my current setup is, I have the Crew Ops Center on a subdomain, and I am trying to figure out how to get it to show on the main site as well. Any help would be greatly appreciated.
Hi!
I don't know if this question has been answered or not, as I could not find a solid answer, but I am running my PHPvms 5.5x on a subdomain, e.g. fly.domain.com, and I want to display a flight map, or just a simple number of pilots, flights, and miles flown, on the non sub-domain (Main Site).
Thanks.