Re: [pylons-discuss] What is the best practice to protect GET request against CSRF attacks?

2014-07-03 Thread Torsten Irländer
Am Donnerstag, 3. Juli 2014 00:32:15 UTC+2 schrieb cornelius: Am 02.07.2014 23:01, schrieb Torsten Irländer: Am Mittwoch, 2. Juli 2014 17:00:02 UTC+2 schrieb Bert JW Regeer: On Jul 2, 2014, at 7:29, Torsten Irländer tor...@irlaender.de wrote: I guess that most people only talk

Re: [pylons-discuss] What is the best practice to protect GET request against CSRF attacks?

2014-07-03 Thread Bert JW Regeer
On Jul 3, 2014, at 00:43 , Torsten Irländer tors...@irlaender.de wrote: Am Donnerstag, 3. Juli 2014 00:32:15 UTC+2 schrieb cornelius: Am 02.07.2014 23:01, schrieb Torsten Irländer: Am Mittwoch, 2. Juli 2014 17:00:02 UTC+2 schrieb Bert JW Regeer: On Jul 2, 2014, at 7:29, Torsten

Re: [pylons-discuss] What is the best practice to protect GET request against CSRF attacks?

2014-07-03 Thread Torsten Irländer
Am Donnerstag, 3. Juli 2014 01:15:41 UTC+2 schrieb Randall Leeds: On Wed, Jul 2, 2014 at 2:01 PM, Torsten Irländer tor...@irlaender.de javascript: wrote: Am Mittwoch, 2. Juli 2014 17:00:02 UTC+2 schrieb Bert JW Regeer: On Jul 2, 2014, at 7:29, Torsten Irländer tor...@irlaender.de

Re: [pylons-discuss] What is the best practice to protect GET request against CSRF attacks?

2014-07-03 Thread Bert JW Regeer
On Jul 3, 2014, at 00:57 , Torsten Irländer tors...@irlaender.de wrote: Hmm... I was thinking of a simple HTML mail with some JS code which gets executed in Alice browser when opening the Mail. Is this problematic to start because the webmailer hopefully escapes and strips such malicious

Re: [pylons-discuss] What is the best practice to protect GET request against CSRF attacks?

2014-07-03 Thread Torsten Irländer
Am Donnerstag, 3. Juli 2014 09:03:32 UTC+2 schrieb Bert JW Regeer: On Jul 3, 2014, at 00:57 , Torsten Irländer tor...@irlaender.de javascript: wrote: Hmm... I was thinking of a simple HTML mail with some JS code which gets executed in Alice browser when opening the Mail. Is this

Re: [pylons-discuss] What is the best practice to protect GET request against CSRF attacks?

2014-07-03 Thread Cornelius Kölbel
Am 03.07.2014 08:43, schrieb Torsten Irländer: Am Donnerstag, 3. Juli 2014 00:32:15 UTC+2 schrieb cornelius: Am 02.07.2014 23:01, schrieb Torsten Irländer: Am Mittwoch, 2. Juli 2014 17:00:02 UTC+2 schrieb Bert JW Regeer: On Jul 2, 2014, at 7:29, Torsten Irländer

Re: [pylons-discuss] What is the best practice to protect GET request against CSRF attacks?

2014-07-03 Thread Bert JW Regeer
On Jul 3, 2014, at 02:48 , Cornelius Kölbel cornelius.koel...@netknights.it wrote: Am 03.07.2014 08:43, schrieb Torsten Irländer: Am Donnerstag, 3. Juli 2014 00:32:15 UTC+2 schrieb cornelius: Am 02.07.2014 23:01, schrieb Torsten Irländer: Am Mittwoch, 2. Juli 2014 17:00:02 UTC+2