# HG changeset patch # User Dan # Date 1260657046 18000 # Node ID 1cd9e6df6f278fc50482c191b8b85934c4bed01d # Parent 1b90f6c41d9c1e5ae3117ee8b283e29be1b925cf Installer: cleaned up CSS header; updated comments in config.php to not say that passwords are stored with AES (as they are now stored with HMAC-SHA1) diff -r 1b90f6c41d9c -r 1cd9e6df6f27 install/images/css/installer.css --- a/install/images/css/installer.css Sat Dec 12 16:45:52 2009 -0500 +++ b/install/images/css/installer.css Sat Dec 12 17:30:46 2009 -0500 @@ -1,7 +1,6 @@ /* * Enano - an open-source CMS capable of wiki functions, Drupal-like sidebar blocks, and everything in between - * Version 1.1.1 - * Copyright (C) 2006-2007 Dan Fuhry + * Copyright (C) 2006-2009 Dan Fuhry * Installation package * installer.css - visual styling rules for the installer * diff -r 1b90f6c41d9c -r 1cd9e6df6f27 install/includes/payload.php --- a/install/includes/payload.php Sat Dec 12 16:45:52 2009 -0500 +++ b/install/includes/payload.php Sat Dec 12 17:30:46 2009 -0500 @@ -253,9 +253,12 @@ define('ENANO_CONSTANTS', ''); } -// The AES encryption key used to store passwords. We have a very specific -// reason for doing this; see the rationale at: +// The AES encryption key used for encrypting various bits of information, +// such as cookies, that should not be editable by users. Read about +// Enano's security model at: // http://docs.enanocms.org/Help:Appendix_B +// This key was at one point used for passwords as well, but this is no +// longer true. \$crypto_key = '$site_key'; EOF;