On Feb 6, Shapira, Yoav had something to say about RE: how to block 

>Hi,
>Google is your friend:
>http://forums.devshed.com/archive/1/2000/08/2/1298

If you use this as your sole solution, I'll turn off Javascript and nail
your server simply for principle.

Ok, not really.

If you use a client-side solution, that doesn't relieve you of the need to
use a server-side solution. A client-side solution is for the *user* so
he/she doesn't have to sit through a reload of the page to display an
error message (or otherwise handle the situation). The server-side
solution is the part that is for your application and server and its
security.

As for one potential solution, this may help:
http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&q=%22synchronizer+token%22


--
mattwarden
mattwarden.com




---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to