[jboss-user] [JBoss Seam] - is link secure?

y_zl do-not-reply at jboss.com
Wed Mar 21 13:06:53 EDT 2007


Hi!

I'd like to know if the links generated by s:link s:button are secure.

for example  
  | <s:link action="#{AA.method}"  value="XXX">
  |  <f:param name="id" value="#{object.id}" />
  | </s:link>
  | 

is it possible for somebody to copy this link to the browser  and modify the object id in the current session so that he could see the content of other objects?

Thanks 

View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4030315#4030315

Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=4030315



More information about the jboss-user mailing list