Hi,
Does anyone work on security mechanism using Cookie
that replace the current implementation.
If not, can anyone point to those classes/methods that
I need to investigate?
Thanks,
Alex Kang
--- "Randal L. Schwartz" <[EMAIL PROTECTED]>
wrote:
> >>>>> "tak" == tak Kang <[EMAIL PROTECTED]> writes:
>
> tak> Does anyone know how to remove a authenticate
> password
> tak> from the client?
>
> You really can't, reliably. That's one of the
> downsides of
> the BasicAuth.
>
> If you demand a new realm, most browsers will stop
> sending the old
> password. But they may ignore that, and send the
> old password anyway.
> If you can control the password, you can stop
> accepting it. :)
>
> tak> I had situation that I want to access my
> secured swiki
> tak> from other workstations, but are not allowed to
> exit
> tak> from the web browser.
>
> Even closing the web browser isn't enough. Most
> browsers now have
> "save this user/password", and once clicked, you've
> got a very long
> memory.
>
> tak> Will it be possible to create some dhtml
> scripts to
> tak> remove password records?
>
> Those won't work everywhere. Some firewalls filter
> Javascript for
> security reasons.
>
> Rather than using BasicAuth, it's better to use
> cookies to "brand" a
> browser, then associate that "brand" with a limited
> time
> authentication on server-side. Don't rely on the
> browser to stop
> sending the cookie... just ignore it after a certain
> timeout. Or
> provide a logout button that removes the validity of
> that brand
> immediately.
>
> I've done that in Perl at
>
http://www.stonehenge.com/merlyn/WebTechniques/col61.html
> - doing the
> same thing with swiki would probably be simpler. :)
>
> --
> Randal L. Schwartz - Stonehenge Consulting Services,
> Inc. - +1 503 777 0095
> <[EMAIL PROTECTED]>
> <URL:http://www.stonehenge.com/merlyn/>
> Perl/Unix/security consulting, Technical writing,
> Comedy, etc. etc.
> See PerlTraining.Stonehenge.com for onsite and
> open-enrollment Perl training!
__________________________________________________
Do You Yahoo!?
Get email alerts & NEW webcam video instant messaging with Yahoo! Messenger
http://im.yahoo.com