W3C home > Mailing lists > Public > www-jigsaw@w3.org > July to August 2001

Jigsaw realm authentication

From: Milum Software <shayes@milum.com>
Date: Tue, 21 Aug 2001 09:42:19 -0500
Message-Id: <4.3.2.7.0.20010821093224.01eb0da0@pop.outer.net>
To: www-jigsaw@w3.org
I'm using Jigsaw version 2.0.5 server on Windows 98 and NT and when I use 
the Jigsaw realm authentication it works fine as long as the user uses an 
upper case letter for the directory I need to authorize access to.

On my server I have a directory "Calendars" full path would be 
"http://192.168.1.7/Calendars" that I have set to request authorization 
before allowing a user to browse to the directory. This works great except 
if the user types a lower case "calendar" "http://192.168.1.7/calendars" 
which lets the user in with out authorization. If anyone could give me any 
info on this problem it would be great. This is a big security hole for us.

Thanks.
Best Regards,

Scott Hayes
Milum Software
800-257-2120 Sales
512-469-2967 Support
http://www.milum.com
Received on Tuesday, 21 August 2001 12:37:55 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Monday, 9 April 2012 12:13:35 GMT