Yes, you should use https instead of http.

________________________________

From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] On Behalf Of Axton
Sent: Tuesday, December 19, 2006 1:40 PM
To: [email protected]
Subject: Re: Voting option when sending mails


** That's still dangerous because you are sending the password and
username in clear text (I assume you are using an http get, providing
the parameters in the url).

Axton Grams


On 12/19/06, Heider, Stephen <[EMAIL PROTECTED]> wrote: 

        ** 
        In the example I gave in my post from a few minutes ago, users
must enter their password in a password field in the email form.  The
password and username are verified by the web app [that receives the
user's post] prior to accepting it. 
         
        Stephen

________________________________

        From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] On Behalf Of Axton
        Sent: Tuesday, December 19, 2006 1:24 PM
        To: [email protected]
        Subject: Re: Voting option when sending mails
        
        
        ** It's possible but not recommended.  Email's with a method
that allows unauthenticated actions is a ripe for abuse.  Why not
redirect them to a mid-tier page where they can be authenticated and
take their action?
        
        Axton Grams
        
        
        On 12/19/06, Sashi M <[EMAIL PROTECTED]> wrote: 

                ** 
                Hi,
                I need to have voting option (Buttons for Approved /
Rejected) while sending mails from Remedy. Is it possible to have? If
yes, can you please tell how it can be done?
                 
                Thanks & Regards, 
                
                Sashi
                
                 

                __________________________________________________
                Do You Yahoo!?
                Tired of spam? Yahoo! Mail has the best spam protection
around 
                http://mail.yahoo.com
__20060125_______________________This posting was submitted with HTML in
it___ 

        
        __20060125_______________________This posting was submitted with
HTML in it___ 
        __20060125_______________________This posting was submitted with
HTML in it___ 


__20060125_______________________This posting was submitted with HTML in
it___ 

_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the 
Answers Are"

Reply via email to