I hit CANCEL.
6. the message "Sorry you are not authorized" appears
7. in the address box I type www.google.com and wait for it to appear
8. I press the BACK button and guess what I see? I see the "Hello" page
with my userid and password from step 2 !! appare
is not so easy because I am using .htaccess. I
guess I'll just require the crypt() of the PW to be in a cookie. Logout
will just put garbage into the cookie. Hopefully no one will discover that
they can hijack someone elses login by just deleting the cookie. :-(
John Henckel
2 matches
Mail list logo