Jump to content

RSS Export Security


Guest Jim Kring

Recommended Posts

Posted

A discussion board may be configured to require that all members log in, in order to see any content of the forum. However, the RSS feeds do not requiring users to log in. This is a major security issue, IMO. I can understand the desire to support a wide variety of RSS readers (and therefore not require logins, for RSS feeds). My suggestion is that you have an RSS feed option to require that users be logged in, in order to read the RSS feed. Thunderbird, for example, is capable of using the FireFox cookie.txt file, which allows it to take advantage of the "remember me" feature in IPB (which saves an authentication cookie).

Thanks for listening.

Posted

I don't think that's even technically possible. You shouldn't make private forums available in public RSS feed in any case ;)

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...