Dan,
I agree that the stolen-URL security hole is real and serious.
Session-control in the stateless http world is quite a trick, and
Ipswitch's method has been to use only URL variables to maintain
sessions.
There are only 2 methods by which a web application can maintain session
(recognize an authenticated user): by passing variables in the URL, or
by storing the session id numbers in a cookie in the user's browser.
I think it's a reasonable request of users to enable cookies in order to
use the WebMail templates. Likewise, I think it's a reasonable request
of Ipswitch to implement cookie-based session control (as an option)
into their next version of the WebMessaging module, which would
effectively eliminate this security hole.
Ron Allen Hornbaker ����
Humankind Systems, Inc. ~
mailto:[EMAIL PROTECTED]
~~HKSI WebMail Templates for IMail v6~~
Global Stylesheet Colors ~ Fast Loads
ActiveX SpellCheck ~ MacIE compatible
Try our demo...... http://mail.hksi.net
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.