Jesse Guardiani writes:

But, if the user logs in using the new resume.html page,
AND their session's hard-timeout has NOT been exceeded,
we take the data from the .sqwebmail-saved file and use
it to replace all current CGI GET and POST data.

The GET/POST data includes the session identifier. A new login will have a different session identifier, which cannot be overridden.


Attachment: pgp00000.pgp
Description: PGP signature

Reply via email to