Re: [SOGo] Session Cookie Obfuscator / Session management uniknsogosession

2010-11-19 Thread Olivier Migeot
Would it be possible to use that to auth other webapps over SOGo? Like some kind of cheap SSO? On Thu, Nov 18, 2010 at 8:28 PM, Ben bugrepor...@vescentphotonics.com wrote: For those who don't want to store basic username:password as user cookie on the browser, we decided to publish the apache

Re: [SOGo] Session Cookie Obfuscator / Session management uniknsogosession

2010-10-25 Thread Ludovic Marcotte
On 10-10-25 2:24 PM, Pascal Gienger wrote: For those who don't want to store basic username:password as user cookie on the browser, we decided to publish the apache module we use here to anonymize the session cookie. [snip] Thanks for this. What's the license of your code? If appropriate, we

Re: [SOGo] Session Cookie Obfuscator / Session management uniknsogosession

2010-10-25 Thread Ben
If you integrate this into SOGo (which would be great -- I do not like the idea of even temp cookies having plaintext passwords), I have a feature request: session timeout. If someone leaves a connection idle for X minutes, session is no longer valid. If I understand how this patch is