Menu

#8 user authentication is not there

open
nobody
broker (5)
5
2001-08-08
2001-08-08
No

When the user logs in, the password is validated
against the UAS. The session id is supposed to be
checked for validity while processing subsequent
requests. Well... it's not. It is possible to bypass
the login screen entirely and use the service.

Discussion


Log in to post a comment.