Only 127.0.0.1 is privileged, right? So can we just not trust 
X-Forwarded-For: 127.0.0.1 no matter who says it, and not worry if 
X-Forwarded-For is abused otherwise?

-- 
Joshua Paine
LetterBlock: Web applications built with joy
http://letterblock.com/
301-576-1920
_______________________________________________
fossil-users mailing list
fossil-users@lists.fossil-scm.org
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

Reply via email to