Scott Wilson created WOOKIE-427:
-----------------------------------

             Summary: Send idkey in header rather than in URL
                 Key: WOOKIE-427
                 URL: https://issues.apache.org/jira/browse/WOOKIE-427
             Project: Wookie
          Issue Type: Improvement
          Components: Server
    Affects Versions: 2.0.0
            Reporter: Scott Wilson


When a widget sends an API request, e.g. to get preferences or set a 
preference, it should include the ID_KEY in a header field rather than in the 
querystring, as this reduces the likelihood of the parameter being extracted 
and misused.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Reply via email to