RE: Security Proposal

M@rcel <[email protected]>
Newsgroups gmane.comp.web.oscommerce.devel
Message-ID <8c7991f114bfc678e5d38e9040e8a2e5@osCommerce-Forums>
This message was sent from: Development
http://forums.oscommerce.com/viewtopic.php?p=164846#164846
----------------------------------------------------------------

If you set the "Force cookie usage" parameter to 'True', no url's with SID are created. Furthermore, sessions are only created when the client (browser, spider) support the use of cookies. Spiders don't support cookies. Hence no sessions are created for spiders.

But beware: The current implementation of the "Privacy and Security proposal" only functions when the top level domains for HTTP and HTTPS are the same. This mostly not true for stores using a shared ssl-certificate. The stores cannot use the "Force Cookie Usage" setting of 'True'.

An addition to the proposal for shared-ssl stores is currently being reviewed. It has not been released, yet.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.