lynx-dev
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

lynx-dev Passwords in the LYNX cache


From: Ilya Zakharevich
Subject: lynx-dev Passwords in the LYNX cache
Date: Tue, 1 May 2001 17:57:17 -0400
User-agent: Mutt/1.2.5i

[Cc to address@hidden

When saving a document into the cache, should not the password entries
be reset by Lynx?

In addition to obvious using History/Visited to reenter the site, here
is another scenario:

  A form-with-a-password-protected site has a "Logout" link, which
  (resets cookies and?) leads to the "login" page to the site.

  Due to the lynx caching, the "login" page is reloaded "from
  history", thus reloaded with all the entries filled.  Including the
  password entry - which is not shown as filled!  So the user may
  think that everything is OK, and walk from the computer - while it
  is enough to click on SUBMIT to enter the sight.

  Or the user may not wait until the page is fully rendered, and not
  even realize that what is going to be shown is a login page, and/or
  that some (all!) fields are filled.

This actually happens with mydomain.com.

Ilya

; To UNSUBSCRIBE: Send "unsubscribe lynx-dev" to address@hidden

reply via email to

[Prev in Thread] Current Thread [Next in Thread]