Spidaman The Defenestrator wrote:
> 
> The point that should be taken is that if one must use a cookie for auth,
> expire it early and often.  What would _really_ be nice is if there were
> a javascript or ecmascribble or whatever it's called object that can _set_
> or _unset_ the auth request headers so one _could_ do a form driven
> authentication that used HTTP standards (basic and digest authentication).

In that case wouldn't you be trusting the user-agent to respect the unset
command?

-jwb

Reply via email to