Re: Web Security concerns

2006-12-01 Thread Sam Gendler
I haven't read that document, but I think a discussion of security within Tapestry is definitely in order, as it has some pretty significant security vulnerabilities which are never even mentioned in the docs. The fact that so much state is stored in the client page by default really leaves the a

Web Security concerns

2006-12-01 Thread Gareth
Hi, Slightly off topic of "tapestry", but I recently came across a document I thought was really useful at highlighting all the potential issues with a website. It's quite long, but, if like me you haven't had to worry much about security on your web projects before - e.g. non public applicati