I sent this posting early in the morning... I didn't see it posted so I sent
it again. People has already replied (thanks all) and now this gets
posted... Hm.
Is this a common problem with cf-talk?

-----Original Message-----
From: Hoag, Claudia (LNG) [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, May 21, 2002 8:22 AM
To: CF-Talk
Subject: sharing sessions due to url.cfid and url.cftoken


I'm trying to think of a way not to allow people to inadvertedly share a
session by sending each other a url with their cfid and cftoken in it. Of
course we can just make sure that those are not passed as url parameters,
but I'm thinking if there's a way to check if this is a session initiated by
someone else.
Do you guys have any ideas?

Thanks


______________________________________________________________________
Signup for the Fusion Authority news alert and keep up with the latest news in 
ColdFusion and related topics. http://www.fusionauthority.com/signup.cfm
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/[email protected]/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

Reply via email to