0 vote
Hi
I recognized, that the form filling mechanism for HTTP connections stays active even after the login. kinda handy as you login automatically after a session timeout! ;)
actually we have a situation, where this "feature" is kinda dangerous. as other form fields on the website use the same id as the one on the loginpage, the admin could accidentially alter contact information or even our client's login to his services.
a possible solution would be to only allow auto filling once or use a timer(fill forms in first 30seconds after opening connection). as this situation probably only applies in rare circumstances, something like this should be a non default option to any http sessions.
or do you have any other ideas?
cheers
chris
Hi,
I added a feature request for that it's a good idea. Thank you
David Hervieux
what's the state on this feature request? i was hoping for it in 6.5 ;)
cheers
Hi,
This is still on the todo list but it was pushed. I will see what I can do for the next small update
David Hervieux
thanks for the quick answer :)
Hi,
This is now in the new beta 6.9.1.0
David Hervieux
great news, thanks!
i'll try it out soon
hi
just did some tests with the current beta 6.9.5.0.
as i didn't notice any new options in the http-session after upgrading from 6.5 i just logged in with the same session but couldn't see any change in behavior. editing a user in this web application still automatically overwrites the username with mine
how is this fix you mentioned supposed to work?
The auto login set the username once and does not retry after 30 seconds if you logoff for example. Maybe the delay was to quick?
David Hervieux
even after 3 minutes it's filling the forms so user, pw and login button are still "monitored"
the fix sound reasonable to me but would be even better if the timeout can be configured per session. in my situation this means i have to wait 30 seconds before i can edit a user and in cases, where i enjoy the automatic session relogon i would be able to disable the timeout.
btw. i'm using Win7x64 with IE 9
edited by arcplace on 1/25/2012