rack-devel archive mirror (unofficial) https://groups.google.com/group/rack-devel
 help / color / mirror / Atom feed
* Should we continue to support session in params?
@ 2010-10-03 17:03 James Tucker
  2010-10-03 17:59 ` Yehuda Katz
  0 siblings, 1 reply; 3+ messages in thread
From: James Tucker @ 2010-10-03 17:03 UTC (permalink / raw)
  To: rack-devel

There's an option in the sessions infrastructure to support sessions via params. It's untested anywhere except in the memcache session specs. I'd like to remove it as it's nothing but an optional security hole. I can't imagine anyone using this for anything sane, but I'm checking here in case I'm wrong.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2010-10-03 18:08 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2010-10-03 17:03 Should we continue to support session in params? James Tucker
2010-10-03 17:59 ` Yehuda Katz
2010-10-03 18:07   ` James Tucker

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).