Ticket Change Details
Not logged in
Overview

Artifact ID: d12636644d64c10c65d6c40ae45141280e28c358
Ticket: 6c68067abb19bad2b1c548f91fc928975a9815c6
Request an option to allow cookies to not rely on IP address
User & Date: anonymous 2010-03-03 01:06:57
Changes

  1. Appended to comment:
    
    <hr><i>anonymous claiming to be Ross Berteig added on 2010-03-03 01:06:57:</i><br>
    See [http://www.mail-archive.com/fossil-users@lists.fossil-scm.org/msg01621.html|this message to fossil-users] from Kyle McKay describing one (largely untested) quick hack to get this effect. I plan to play with this a little myself since I would like to not loose sessions when working with tickets on my internal server over a VPN from home.
    
    The big web community sites do this (e.g. facebook, Yahoo, Google) and don't seem to be hugely worried about security issues so it must be possible to achieve. Whether it is practical to achieve and still maintain "enough" security is not obvious to me.
    
    
  2. resolution changed to: "Open"