|
Posted by patpro ~ Patrick Proniewski on 06/20/07 22:17
In article <1182359802.321460.10040@o61g2000hsh.googlegroups.com>,
shimmyshack <matt.farey@gmail.com> wrote:
> > And, by the way, in that context, i don't see the point of using a
> > "<LimitExcept GET HEAD OPTIONS>" block to ask for authentication.
> >
>
> i think it's so that browsers can see the content without being asked
> for credentials, whereas any agent which tries to use other verbs will
> be required to authenticate. but explain your objection - I have been
> wrong before!!!
if you want to protect your code, you need to activate the
authentication for every verb.
patpro
--
http://www.patpro.net/
Navigation:
[Reply to this message]
|