https://bugs.freedesktop.org/show_bug.cgi?id=57248
Priority: high
Bug ID: 57248
CC: [email protected]
Assignee: [email protected]
Summary: WebDAV: don't send Basic Auth via http
Severity: major
Classification: Unclassified
OS: All
Reporter: [email protected]
Hardware: Other
Status: ASSIGNED
Version: unspecified
Component: CalDAV/CardDAV
Product: SyncEvolution
SyncEvolution sends Basic Auth in its initial request, to avoid round-trips. If
http with Digest Auth is used, then this behavior exposes the credentials.
SyncEvolution should only send Basic Auth over https.
See bug #56240 comment #4.
--
You are receiving this mail because:
You are on the CC list for the bug.
You are the assignee for the bug.
_______________________________________________
Syncevolution-issues mailing list
[email protected]
http://lists.syncevolution.org/listinfo/syncevolution-issues