On Tuesday, January 7, 2003, at 08:37 PM, Paul Allen Rice wrote:

I've noticed that when I log out of the admin page for one list, go to
another and login there, then come back to the first list, all without
shutting down my browser, Mailman allows me back into the first list admin
area without requesting a login.
When you hit "logout", Mailman removes the contents of the cookie (but leaves the cookie itself until you exit the browser), so this really shouldn't work. If your browser allows you to inspect the contents of the cookies you have stored you can confirm this is working.

When you say "allows me back", does that mean by hitting the back button, or re-entering the URL? The back button will display whatever was there before, but you shouldn't be able to modify anything without re-authenticating.

Is it possible that your browser is auto-completing the login form?

Bryan


------------------------------------------------------
Mailman-Users mailing list
[EMAIL PROTECTED]
http://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://www.python.org/cgi-bin/faqw-mm.py
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/

This message was sent to: [email protected]
Unsubscribe or change your options at
http://mail.python.org/mailman/options/mailman-users/archive%40jab.org


Reply via email to