> From: Julie Fellenz [mailto:julie.fell...@doit.wisc.edu]
> Subject: Re: where to set value of ALLOW_EQUALS_IN_VALUE property
> 
> Will this property (ALLOW_EQUALS_IN_VALUE) still provide security
> required for confidential data?

If you're sending confidential data in a cookie over an unencrypted connection, 
then it's not really confidential, is it?

If you are using an encrypted connection, then why does it matter where the 
parsing stops?

 - Chuck


THIS COMMUNICATION MAY CONTAIN CONFIDENTIAL AND/OR OTHERWISE PROPRIETARY 
MATERIAL and is thus for use only by the intended recipient. If you received 
this in error, please contact the sender and delete the e-mail and its 
attachments from all computers.


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to