Re: Wappush Contains Username/Password
Stipe Tolj <[email protected]>
| Newsgroups | gmane.comp.mobile.kannel.devel |
|---|---|
| Organization | tolj.org system architecture |
| Message-ID | <[email protected]> |
Mathieu Bruneau schrieb:
> Hi,
>
> We remark today that our wappush were containing the credentials of the ppg-username (at least transmitted through the connection). After looking through the source I found that headers were usually removed after consumption (X-Kannel-*) for example. However the Authorization header weren't "consume" after authentification and thus are sent.
>
> Did I miss something and they are supposed to be removed somewhere else or is there any reason for keeping them there ?
>
> Attached the patch I think could solve this (adding 1 line )
convinced me ;) +1, commited to cvs:
2007-12-21 Stipe Tolj <stolj at kannel.org>
* gw/wap_push_ppg_pushuser.c: remove HTTP Authorization header which is
encoded in the bytestream. Thanks to Mathieu Bruneau
<Mathieu.Bruneau at gameloft.com> for reporting and providing patch.
[Msg-Id: <[email protected]>]
Thanks a lot!
Stipe
-------------------------------------------------------------------
Kölner Landstrasse 419
40589 Düsseldorf, NRW, Germany
tolj.org system architecture Kannel Software Foundation (KSF)
http://www.tolj.org/ http://www.kannel.org/
mailto:st_{at}_tolj.org mailto:stolj_{at}_kannel.org
-------------------------------------------------------------------