List Info

Thread: Bypass login with friendly URL




Bypass login with friendly URL
user name
2007-03-12 15:21:27
Hello,

I upgraded to the new integration build. No problems, and
the improved
navigation is appreciated.

I seem to have found a security flaw though. The
"friendly URL"
feature (which we will use for integration with the scm)
bypasses the
need for login. Even when I am logged out, I can see the
issues in a
non-public tracker. Is it only me?

/Staffan

------------------------------------------------------------
-------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the
chance to share your
opinions on IT & business topics through brief
surveys-and earn cash
http://www.techsay.com/default.
php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
j-trac-users mailing list
j-trac-userslists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/j-trac-use
rs

Re: Bypass login with friendly URL
user name
2007-03-13 04:17:48
Hmm, that needs to be looked into, thanks!

On 3/13/07, JTrac users mailing-list < j-trac-userslists.sourceforge.net">j-trac-userslists.sourceforge.net > wrote:
Hello,

I upgraded to the new integration build. No problems, and the improved
navigation is appreciated.

I seem to have found a security flaw though. The "friendly URL"
feature (which we will use for integration with the scm) bypasses the
need for login. Even when I am logged out, I can see the issues in a
non-public tracker. Is it only me?

/Staffan

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys-and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
j-trac-users mailing list
j-trac-userslists.sourceforge.net">j-trac-userslists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/j-trac-users

[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )