Re: CSRF on multiple tomcat instances

2012-11-07 Thread Pid
On 06/11/2012 03:59, Christopher Schultz wrote: > Wilfred, > > On 11/5/12 4:08 AM, Wilfred Duizers wrote: >> When a user clicks a link in the webapplication running on Tomcat >> instance 1 (portal) an application running on Tomcat instance 2 is >> opened. Is it possible to send the nonce with th

Re: CSRF on multiple tomcat instances

2012-11-05 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wilfred, On 11/5/12 4:08 AM, Wilfred Duizers wrote: > When a user clicks a link in the webapplication running on Tomcat > instance 1 (portal) an application running on Tomcat instance 2 is > opened. Is it possible to send the nonce with the link? Be

RE: CSRF on multiple tomcat instances

2012-11-05 Thread Wilfred Duizers
yes it would :P Do you see a solution anywayboth tomcat instances use the same domain https://www.example.com They use isapi Van: Pid * [p...@pidster.com] Verzonden: maandag 5 november 2012 9:30 Aan: Tomcat Users List Onderwerp: Re: CSRF on multiple

Re: CSRF on multiple tomcat instances

2012-11-05 Thread Pid *
On 2 Nov 2012, at 14:23, Wilfred Duizers wrote: > Hello, > > I am running 2 Tomcat instances on 1 server. So far nothing special :-) > Both: > Apache Tomcat/7.0.25 > JVM 1.6.0_20-b02 > > When a user clicks a link in the webapplication running on Tomcat instance 1 > (portal) an application runnin