[rt-users] Check ticker history w/o login.

Jesse jesse at fsck.com
Wed Dec 13 17:07:58 EST 2000


Look at the html of the login screen.
You can add hidden fields for username and password to your mini-form,
but that means that any user can trivially find out that username and password....

	-j
On Wed, Dec 13, 2000 at 02:00:47PM -0800, Matthew Valdez wrote:
> Hey all,
> 
>     I'd like to be able to allow anyone to check the status of a ticket
> without logging in, with for example, the following html:
> 
> <form method=get action="/rt/webrt.cgi"><input type="hidden"
> name="display" value="History"><input type="submit" value="Display
> request #"><input size=6 name="serial_num"></form>
> 
> This just kicks me into the login screen.  I'm not really sure how the
> access control works.
> 
> 
> _______________________________________________
> rt-users mailing list
> rt-users at lists.fsck.com
> http://lists.fsck.com/mailman/listinfo/rt-users
> 

-- 
jesse reed vincent -- root at eruditorum.org -- jesse at fsck.com 
70EBAC90: 2A07 FC22 7DB4 42C1 9D71 0108 41A3 3FB3 70EB AC90

Pelcgb-serrqbz abj!




More information about the rt-users mailing list