[Freeipa-devel] [PATCH] resend enable sessions in the GUI

Rob Crittenden rcritten at redhat.com
Thu Jan 10 21:07:38 UTC 2008


This enables server-side file-based sessions on the server side. In 
production the sessions will be stored in /var/cache/ipa.

I've also added a simple mechanism to try ensure that a record that is 
being updated is the record that was last edited. This is an attempt 
around a phishing attack that might trick a user to click on a link that 
will do a POST and update their password in the UI.

rob
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-568-sessions.patch
Type: text/x-patch
Size: 3811 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20080110/7d9741c1/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3245 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20080110/7d9741c1/attachment-0001.bin>


More information about the Freeipa-devel mailing list