Re: [fwd] Policy Languages Interest Group e-mail address confirmation (from: web-human@w3.org)

Thomas Roessler <tlr@w3.org> writes:

> Note that the source IP address given here is the one of the mirror
> used.

Please use HTTP_X_FORWARDED_FOR if present instead of REMOTE_ADDR for
when the wiki requests are being proxied.

> From: web-human@w3.org
> Subject: Policy Languages Interest Group e-mail address confirmation
> To: ThomasRoessler <tlr@w3.org>
> Date: Thu, 06 Dec 2007 22:02:41 -0500
>
> Someone, probably you from IP address 128.30.52.38, has registered an
> account "ThomasRoessler" with this e-mail address on Policy Languages Interest Group.
>
> To confirm that this account really does belong to you and activate
> e-mail features on Policy Languages Interest Group, open this link in your browser:
>
> http://www.w3.org/Policy/pling/wiki/Special:Confirmemail/asdf
>
> If this is *not* you, don't follow the link. This confirmation code
> will expire at 03:02, 14 December 2007.

Following the link provided enabled the account.  HTTP GET should not
change state in a database, there should be a second step after the
GET to indicate one wishes to create the account, form or just button
that gives HTTP POST action.

http://www.w3.org/2001/tag/doc/whenToUseGet.html#checklist

-- 
Ted Guild <ted@w3.org>
W3C Systems Team
http://www.w3.org

Received on Tuesday, 11 December 2007 17:23:56 UTC