And HTTP POST, not GET.

**
Yes, you should use https instead of http.



--------------------------------------------------------------------------------
From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] On Behalf Of Axton
Sent: Tuesday, December 19, 2006 1:40 PM
To: [email protected]
Subject: Re: Voting option when sending mails


** That's still dangerous because you are sending the password and
username in clear text (I assume you are using an http get, providing
the parameters in the url).

Axton Grams


On 12/19/06, Heider, Stephen <[EMAIL PROTECTED]> wrote:
**
In the example I gave in my post from a few minutes ago, users must
enter their password in a password field in the email form.  The
password and username are verified by the web app [that receives the
user's post] prior to accepting it.

Stephen



--------------------------------------------------------------------------------
From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] On Behalf Of Axton
Sent: Tuesday, December 19, 2006 1:24 PM
To: [email protected]
Subject: Re: Voting option when sending mails


** It's possible but not recommended.  Email's with a method that
allows unauthenticated actions is a ripe for abuse.  Why not redirect
them to a mid-tier page where they can be authenticated and take their
action?

Axton Grams


On 12/19/06, Sashi M <[EMAIL PROTECTED]> wrote:
**
Hi,
I need to have voting option (Buttons for Approved / Rejected) while
sending mails from Remedy. Is it possible to have? If yes, can you
please tell how it can be done?

Thanks & Regards,
Sashi

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com __20060125_______________________This posting
was submitted with HTML in it___


__20060125_______________________This posting was submitted with HTML in it___
__20060125_______________________This posting was submitted with HTML in it___

__20060125_______________________This posting was submitted with HTML
in it___ __20060125_______________________This posting was submitted
with HTML in it___

_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the Answers 
Are"

Reply via email to