#9822: Cookies are still causing problems in SageNB (Safari)
--------------------------------------+-------------------------------------
   Reporter:  timdumol                |       Owner:  jason, was  
       Type:  defect                  |      Status:  needs_review
   Priority:  major                   |   Milestone:  sage-4.6    
  Component:  notebook                |    Keywords:              
     Author:  Jason Grout, Tim Dumol  |    Upstream:  N/A         
   Reviewer:                          |      Merged:              
Work_issues:                          |  
--------------------------------------+-------------------------------------

Comment(by timdumol):

 It is insecure to let any site under the domain to access the cookie
 (cross-site scripting). I've made the port 443 if the notebook is secure.
 It also poses a problem if (in the admittedly rare case) the user decides
 to forward several ports to one notebook server.

 `getHeader()` returns None if the header is not found, so it works either
 way.

-- 
Ticket URL: <http://trac.sagemath.org/sage_trac/ticket/9822#comment:11>
Sage <http://www.sagemath.org>
Sage: Creating a Viable Open Source Alternative to Magma, Maple, Mathematica, 
and MATLAB

-- 
You received this message because you are subscribed to the Google Groups 
"sage-trac" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/sage-trac?hl=en.

Reply via email to