RE: Security Proposal

Ross <[email protected]>
Newsgroups gmane.comp.web.oscommerce.devel
Message-ID <5a4b0761baf0101b483070a72596dd93@osCommerce-Forums>
This message was sent from: Development
http://forums.oscommerce.com/viewtopic.php?p=149585#149585
----------------------------------------------------------------

[quote]To my mind, this removes the session ID from the URL presumably by storing it in another environmental variable on Apache?[/quote]
I don't think so, but I never got it to work without problems.  AFAIK, it just replaces ? and & in the URL with /, but does nothing with the SID.

[quote]Does this mean that there work has been included in the recent snapshot or still has to be included?[/quote]
Marcel has come up with a few different ways of making it happen, so I kind of just took a back seat on working on it myself and have just helped in "testing" as of late.  I still do have my version working, however.

The last I heard, Marcel was waiting to hear back from Harald about taking the next step....I guess determining which method would be best.  It's not in the CVS yet and if no version actually makes it in, I would imagine that a contribution would be made, but I certainly have no idea on a timeframe...
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.