>>>>> "Denys" == Denys Vlasenko <[EMAIL PROTECTED]> writes:

Hi,

 Denys> But those are different situations! In second case, we should
 Denys> not check dummy credentials ":", we already know that user
 Denys> shall not get the page.
 >> 
 >> True, it's more effecient to not do the double check.

 Denys> It's not an efficiency question. check_user_passwd(urlcopy, ":")
 Denys> might SUCCEED, and thus user who supplied wrong user:password
 Denys> pair will be granted access.

Ahh yes.

-- 
Bye, Peter Korsgaard
_______________________________________________
busybox mailing list
[email protected]
http://busybox.net/cgi-bin/mailman/listinfo/busybox

Reply via email to