Re: Hiding passwords found in redirect URLs

2008-09-13 Thread Thomas Corthals
Micah Cowan wrote: Note: Saint Xavier has already written a fix for this, so it's not actually a question of whether it's worth the bother, just whether it's actually desired behavior. Since it's desired in some situations but maybe not in others, the best solution would be to provide a

Re: Hiding passwords found in redirect URLs

2008-09-13 Thread Micah Cowan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thomas Corthals wrote: Micah Cowan wrote: Note: Saint Xavier has already written a fix for this, so it's not actually a question of whether it's worth the bother, just whether it's actually desired behavior. Since it's desired in some

Hiding passwords found in redirect URLs

2008-09-12 Thread Micah Cowan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 https://savannah.gnu.org/bugs/index.php?21089 The report originator is copied in the recipients list for this message. The situation is as follows: the user types wget http://foo.com/file-i-want;. Wget asks the HTTP server for the appropriate file,