Since cron.php now requires a key to be run, cron-curl.sh and cron-lynx.sh will result in an access denied error.

I don't have a patch yet, but there probably needs to be another validation method for a GET request, or someway to invoke drupal_cron_run() from the system itself.

Comments

kevin hankens’s picture

StatusFileSize
new1.36 KB

Here's a patch that appends "?cron_key=" to the url http://example.com/cron.php. I also added help text to both cron-curl.sh and cron-lynx.sh instructing the users:

# A unique cron key is required to call cron.php.
# Please visit http://example.com/admin/reports/status
# to retrieve the necessary URL including cron key.

Since the key is only set during installation, I think that this will be a safe and reliable way to retrieve it.

kevin hankens’s picture

Status: Active » Needs review
moshe weitzman’s picture

We might as well also say "Paste that long string to the end of the line below."

kevin hankens’s picture

StatusFileSize
new1.54 KB

Here's a slight revision:

# A unique cron key is required to call cron.php.
# Please visit http://example.com/admin/reports/status to retrieve the necessary 
# URL including cron key. Paste the entire string below making sure to include
# the unique string following ?cron_key=.

Patch attached.

mnicholas’s picture

Imagine the nightmare of a multi-site install with a different "cron_key" for each site. Why not allow cron to be run without a key when:

$_SERVER['REMOTE_ADDR'] == '127.0.0.1'

Then you can run curl so:

curl --silent --compressed --interface 127.0.0.1 http://example.com/cron.php

or wget with: --bind-address=127.0.0.1

At least then you can pen a script to loop through the all the sites.

Fetching http://example.com/cron.php from another script can cause a deadlock on a system where http requests are queued.

kevin hankens’s picture

We've found that drush is a good fit for that exact scenario. drush core-cron invokes drupal_cron_run() directly, bypassing the need to know the unique cron key for each site.

EvanDonovan’s picture

I think most people who want to run cron via command line already use drush, so #5 is probably not a significant problem.

kevin hankens’s picture

Issue tags: +Documentation

Tagging as documentation.

eric115’s picture

Issue summary: View changes
Status: Needs review » Closed (outdated)
Issue tags: +Bug Smash Initiative

I think it's safe to close this now based on the age of the issue.