struts-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From dun...@sapio.co.uk (Duncan Harris)
Subject Re: Transaction Token check required before form populate
Date Thu, 01 Jan 1970 00:00:00 GMT
keithbaconstruts@yahoo.com (Keith) wrote:

> Isn't it easy enough to test which form you came from to decide whether to call
> isTokenValid()?

Not a problem in this respect. The problem is the URL for a GET (see below).


> > However the URL is no longer very clean.

> I don't get what you mean.

It contains something like:

org.apache.struts.taglib.html.TOKEN=32ea43086bf2732216d4eb96bf22d44

which prevents possible caching of the GET request for example.


Duncan Harris
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hartford, Cheshire, U.K., Tel: 07968 060418
Looking for STRUTS contract work in the U.K.

--
To unsubscribe, e-mail:   <mailto:struts-user-unsubscribe@jakarta.apache.org>
For additional commands, e-mail: <mailto:struts-user-help@jakarta.apache.org>


Mime
View raw message