[Typo3-dev] Typo3 backend login and proxy servers

Kasper Skårhøj kasper2004 at typo3.com
Sat Aug 7 23:06:00 CEST 2004


Two things changed:

1) backend sessions are locked to the HTTP_USER_AGENT value so sessions
cannot easily be hijacked.
2) backend sessions are locked to the IP address meaning that a change
in IP adress will throw you off.

- kasper

On Sat, 2004-08-07 at 18:10, Kristian Kristensen wrote:
> Hi all,
> 
> When I connect to <mysite>/typo3 and try to logon I get an error, saying
> that cookies must be enabled for me to use the system. However, the problem
> is only there when I use a proxy server. I'm using Typo3 version 3.6.2
> With version 3.5 I didn't have these problems.
> 
> So the question is: has anything changed involving cookie handling upon
> backend login from version 3.5 to 3.6?
> 
> Of course the simple solution would be that the proxy server is set up to
> drop any cookies, but that doesn't explain why it used to work in v. 3.5...
> 
> Best,
> Kristian Kristensen
> 
> 
> _______________________________________________
> Typo3-dev mailing list
> Typo3-dev at lists.netfielders.de
> http://lists.netfielders.de/cgi-bin/mailman/listinfo/typo3-dev
-- 
- kasper

--------
Please notice NEW EMAIL ADDRESS for 2004!! (due to SPAM-contamination)
	
"kasper2004 at typo3.com"






More information about the TYPO3-dev mailing list