Issue81

Title [patch] advise against using include_ip
Priority feature Status resolved
Superseder Nosy List paj, tseaver
Assigned To tseaver Topics

Created on 2009-05-19.00:19:52 by paj, last changed 2009-06-11.09:25:47 by paj.

Files
File name Uploaded Type Edit Remove
include_ip.patch paj, 2009-05-19.00:19:52 application/octet-stream
Messages
msg209 (view) Author: tseaver Date: 2009-05-20.07:33:18
I have checked in a modified version of this patch (I put the
advisory in an ReST '.. note::').
msg197 (view) Author: paj Date: 2009-05-19.00:20:47
Got 500 internal server error when submitting the bug
msg196 (view) Author: paj Date: 2009-05-19.00:19:52
Suggest add this note to doc on AuthTktCookiePlugin advising against using
include_ip
BTW, the 3% figure comes from here:
http://westpoint.ltd.uk/advisories/Paul_Johnston_GSEC.pdf
History
Date User Action Args
2009-06-11 09:25:47 paj set status: chatting -> resolved
2009-05-20 07:33:18 tseaver set status: resolved -> chatting
assignedto: tseaver
messages: + msg209
nosy: + tseaver
2009-05-19 00:20:47 paj set status: unread -> resolved
messages: + msg197
2009-05-19 00:19:52 paj create