[dev] Fwd: [Bug 1246] New - session hijacking using referer URL

Chuck Hagenbuch chuck at horde.org
Wed May 14 05:59:19 PDT 2003


Quoting Mike Cochrane <mike at graftonhall.co.nz>:

> This has be discussed a number of times that I remember, may have been in
> #horde and not the list. But a 'de-referer' would definatly be useful for
> external links.

Okay - I don't see strong reasons not to go that way. What about protecting
the dereferrer from abuse? Or is that not a concern (use from outside
Horde)?

-chuck

--
Charles Hagenbuch, <chuck at horde.org>
The alligators were there, too, in a bathtub inside the house.


More information about the dev mailing list