On Tue, 5 Feb 2002, Rodent of Unusual Size wrote:

> [EMAIL PROTECTED] wrote:
> >
> >   List files that would result in HTTP_UNAUTHORIZED in addition to
> >   successes and redirections, since there's a chance the client will
> >   actually have the proper authorization to retrieve them.
>
> -1 (yes, a veto).  Standard security practice: you don't
> expose even meta-information without knowing the user can
> access it.

Reverted.

--Cliff

--------------------------------------------------------------
   Cliff Woolley
   [EMAIL PROTECTED]
   Charlottesville, VA


Reply via email to