Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Stefano Mazzocchi
Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the continuation ID from a ses

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Stefano Mazzocchi
forwarded message: From: "Chris Haynes" <[EMAIL PROTECTED]> Date: 28 September 2005 13:04:53 BDT To: "Jetty Discuss" <[EMAIL PROTECTED]> Subject: [jetty-discuss] Microsoft IE7 compromise of session security Reply-To: [EMAIL PROTECTED] List-Id: Discussion for

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Peter Hunsberger
On 10/3/05, Sylvain Wallez <[EMAIL PROTECTED]> wrote: > Tony Collen wrote: > > > Pier Fumagalli wrote: > > > >> I found this on the Jetty list, and thought it was relevant as in the > >> examples we tend to encode the continuation ID into the URL... > >> > >> This is f***ing scary!!! > >> > >>

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Sylvain Wallez
Leszek Gawron wrote: Sylvain Wallez wrote: Tony Collen wrote: Maybe it's time we make Cocoon automatically pull the continuation ID from a session tied to a cookie. That won't work as a continuation is related to the page displayed in the browser rather than to the browser itself, as is

Re: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Bertrand Delacretaz
Le 3 oct. 05, à 12:04, Sylvain Wallez a écrit : ...I'm with Reinhard: let's tie continuations to sessions, which should be fine for 99.9% of the use cases. Even if the continuation ID is in the URL, it won't be accessible without the session id cookie... +1 -Bertrand smime.p7s Description:

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Leszek Gawron
Sylvain Wallez wrote: Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the c

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Sylvain Wallez
Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the continuation ID from a

Re: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Torsten Curdt
On 03.10.2005, at 02:30, Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull th

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Leszek Gawron
Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the continuation ID from a s

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Reinhard Poetz
Tony Collen wrote: Maybe it's time we make Cocoon automatically pull the continuation ID from a session tied to a cookie. Since Cocoon 2.1.6 you can tie Cookies to a user's session. Maybe we should change the default value with our next release for this setting. -- Reinhard Pötz

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Tony Collen
Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the continuation ID from a session tied to a cooki

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Antonio Gallardo
Pier Begin forwarded message: From: "Chris Haynes" <[EMAIL PROTECTED]> Date: 28 September 2005 13:04:53 BDT To: "Jetty Discuss" <[EMAIL PROTECTED]> Subject: [jetty-discuss] Microsoft IE7 compromise of session security Reply-To: [EMAIL PROTE

Re: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Pier Fumagalli
On 2 Oct 2005, at 23:17, Sylvain Wallez wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Yep. And doesn't the same already happen with the Google toolb

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Sylvain Wallez
le to have the page rank? Same applies also to the PageRank Firefox extension... Sylvain Begin forwarded message: From: "Chris Haynes" <[EMAIL PROTECTED]> Date: 28 September 2005 13:04:53 BDT To: "Jetty Discuss" <[EMAIL PROTECTED]> Subject: [jetty-discuss

Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Pier Fumagalli
: "Jetty Discuss" <[EMAIL PROTECTED]> Subject: [jetty-discuss] Microsoft IE7 compromise of session security Reply-To: [EMAIL PROTECTED] List-Id: Discussion for Jetty development. discuss.lists.sourceforge.net> Everyone concerned with data security and privacy should read the