Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Leszek Gawron
Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the continuation ID from a

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Sylvain Wallez
Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the continuation ID from a

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Leszek Gawron
Sylvain Wallez wrote: Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Sylvain Wallez
Leszek Gawron wrote: Sylvain Wallez wrote: Tony Collen wrote: Maybe it's time we make Cocoon automatically pull the continuation ID from a session tied to a cookie. That won't work as a continuation is related to the page displayed in the browser rather than to the browser itself, as

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Peter Hunsberger
On 10/3/05, Sylvain Wallez [EMAIL PROTECTED] wrote: Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Stefano Mazzocchi
Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Wow, this will kill either kill urlencoding or IE. Seems like good news for firefox, though. Pier Begin

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-03 Thread Stefano Mazzocchi
Tony Collen wrote: Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the continuation ID from a

Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Pier Fumagalli
I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Begin forwarded message: From: Chris Haynes [EMAIL PROTECTED] Date: 28 September 2005 13:04:53 BDT To: Jetty Discuss [EMAIL

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Sylvain Wallez
Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Yep. And doesn't the same already happen with the Google toolbar, which certainly send the URL to Google to

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Antonio Gallardo
Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! For the records, don't think they just invented the cool water today! Anti-phishing bars for browsers is not

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Tony Collen
Pier Fumagalli wrote: I found this on the Jetty list, and thought it was relevant as in the examples we tend to encode the continuation ID into the URL... This is f***ing scary!!! Pier Maybe it's time we make Cocoon automatically pull the continuation ID from a session tied to a

Re: Fwd: [jetty-discuss] Microsoft IE7 compromise of session security

2005-10-02 Thread Reinhard Poetz
Tony Collen wrote: Maybe it's time we make Cocoon automatically pull the continuation ID from a session tied to a cookie. Since Cocoon 2.1.6 you can tie Cookies to a user's session. Maybe we should change the default value with our next release for this setting. -- Reinhard Pötz