#1798 new defect

Segregate gateway HTTP ports: one for raw bytes and one for generated WUI pages — at Initial Version

Reported by: davidsarah Owned by:
Priority: major Milestone: soon
Component: code-frontend-web Version: 1.9.2
Keywords: wui same-origin security capleak Cc: freddyb
Launchpad Bug:

Description

This is a complementary approach to #1797 and #827 for solving the same-origin security problems described in #615.

Note that it has no security benefit on Internet Explorer because IE treats all ports on a host as being in the same origin. It does have benefit on other browsers.

Change History (0)

Note: See TracTickets for help on using tickets.