> I believe it's done that way because that's how HTTP basic
> authentication works.
>
> That allows you to use cflogin to authenticate a person who
> has already been authenticated that way.

I don't see why the CFLOGIN cookie would have to contain the exact same data
format as an HTTP header for Basic Authentication. In any case, if you're
correct, they presumably won't be able to change the mechanism for
generating CFLOGIN cookies.

Dave Watts, CTO, Fig Leaf Software
http://www.figleaf.com/
phone: 202-797-5496
fax: 202-797-5444
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings] [Donations and Support]

Reply via email to