> Hey Paul, yes, the control panel would add the domain to a config file,
> then that would be allowed to login....  Regardless of the URL they use,
> I am thinking if they login with [EMAIL PROTECTED] and domain.com is not
> in the config file they cannot login, make sense?

argh.  not thinking entirely straight.

what i sent could be bypassed if a user was clever enough to know another
domain you were hosting and went there to log on.  that is, your idea of
checking the user's login name is more thorough.  hold on and i'll make
that change...

 - paul




-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
--
squirrelmail-users mailing list
List Address: [EMAIL PROTECTED]
List Archives:  http://sourceforge.net/mailarchive/forum.php?forum_id)95
List Info: https://lists.sourceforge.net/lists/listinfo/squirrelmail-users

Reply via email to