While fixing the login-redirect.jsp issue, I noticed some keys in the security.xml.

We probably should be telling installing admins to change the keys to their own site-specific values from the values in the distribution in the security.xml after installing.

I haven't checked the Acegi code yet, but my fear is that RememberMe cookies might be forged with knowledge of these keys.

Matt?

--a.

Reply via email to