RE: Issue 5; GET vs GetLastTradePrice
"David Orchard" <[email protected]>
| Newsgroups | gmane.comp.web.services.ws-arch |
|---|---|
| Message-ID | <[email protected]> |
> -----Original Message----- > From: Mark Baker [mailto:[email protected]] > Sent: Thursday, January 02, 2003 11:13 AM > To: David Orchard > Cc: [email protected] > Subject: Re: Issue 5; GET vs GetLastTradePrice > > > 3. The web security model is pretty badly broken in some > areas. The very > > fact that a server can't time-out an HTTP log-in, > > Erm, yes it can. A server can send a 401 any time it feels like it, > for any reason. > So you think authentication and time-outs on the Web are just fine and working as designed? Cheers, Dave