« Return to Thread: Trails 1.2 & OGNL issues
Yes, this is what I did now...but what about the automatic session-id fallback? Or is it possible to switch this off ?
Session IDs are bad - unless they change with every request....and/or are ip address related (but ips change, too).
-------- Original-Nachricht --------
> Datum: Mon, 26 May 2008 09:26:56 -0700
> Von: "Kalle Korhonen" <kalle.o.korhonen@...>
> An: users@...
> Betreff: Re: [trails-users] Trails Security unsecure ???
> Use POST to send the login form via https. These certainly are easily
> configurable but not necessarily the best defaults when you first start
> developing a web application - which is why Trails and web app frameworks
> typically have the simplest options for demonstration purposes.
>
> Kalle
>
>
> On Mon, May 26, 2008 at 7:41 AM, Tobias Marx <superoverdrive@...>
> wrote:
>
> > There are some issues about Trails Security that might maybe
> > be configurable - I hope they are.
> >
> > By default, Trails Security is quite unsecure:
> >
> > 1. Username/password on the login page are passed via GET in the URL !!!
> > 2. If Cookies are disabled, Session IDs are used - that are easily
> > hijackable....
> >
> > Is there a workaround?
> >
> > Thanks!
> >
> >
> > Tobias
> >
> > ---------------------------------------------------------------------
> > To unsubscribe from this list, please visit:
> >
> > http://xircles.codehaus.org/manage_email
> >
> >
> >
---------------------------------------------------------------------
To unsubscribe from this list, please visit:
http://xircles.codehaus.org/manage_email
« Return to Thread: Trails 1.2 & OGNL issues
| Free embeddable forum powered by Nabble | Forum Help |