Help protect the website from attackers or bad actors, by identifying, preventing, or mitigating security vulnerabilities.

Require Login

Provides catch-all solution to easily require user authentication on all pages. Quick to configure and fully compatible with any other access control systems.

443 Session

HTTPS

The 443 Session module makes using HTTPS on your site simple. It is most useful for doing mixed HTTPS where some pages are sent via HTTP, and others via HTTPS. It can be used to protect credit card transactions or to protect against session hijacking (via tools such as Firesheep).

Content protector

Content protector allows an arbitrary directory to be protected by Drupal authentication.

Good Site List

The Good Site List input filter disables HTML forms whose domains are not part of an approved list.

Advanced Comment Trigger

Advanced Comment Trigger provides a new trigger category allowing automatic unpublishing of comments based on more fine-grained criteria than the default "new comment added" trigger.

OpenID Synchronization Framework

logo_openid.png

Description

Need to add a list of admin OpenIDs to many websites and not lose sanity while maintaining that list across all servers? This module is for you.

You can still maintain arbitrary list of OpenIDs on each site, but the framework ensures a list of allowed and banned OpenIDs (for the "admin" user), in addition to the local list.

This tool is for Drupal service-providers that maintain many websites and need to give admin access to a number of people, across multiple websites, for maintenance and support purposes.

Requirements

  1. Install Libraries module (D5 version has a "safe" backport embedded): http://drupal.org/project/libraries
  2. Download YAML library from: http://code.google.com/p/spyc/
    Extract zip file and install spyc.php under "spyc" sub-folder of sites/all/libraries (or sites/sitename/libraries).

Also, please make sure to read README.txt accompanying the module, for installation and configuration instructions.

Maturity Status

Both client and server modules of the framework have been thoroughly tested in development and have no known issues. However, these modules are new, and have been used in production, only for a limited duration.

Credits

Pages

Subscribe with RSS Subscribe to RSS - Security