BASIC èªè¨¼ã§ãã°ã¢ã¦ããå¯è½ã«ããæ¹æ³
Cookie ã§ãã°ã¤ã³ç¶æ ã管çããã°ããããããã®ããªã
ã¾ãããã°ã¤ã³ãã¿ã³ãæ¼ããæãã ããis_logged_on ãçã«ããã
HTTP/1.1 Authorization Required Set-Cookie: is_logged_on=1 WWW-Authenticate: Basic realm="Hoge123456" ...
ãµã¼ãå´ã§ã¯ãBasic èªè¨¼ã®ãã¹ã¯ã¼ããããããã¤ãis_logged_on ã®å¤ãçã§ãããã¨ããã§ãã¯ããã°ããã
GET / HTTP/1.1 Cookie: is_logged_on=1 Authorization: Basic ... ... HTTP/1.1 200 OK ...
ã§ããã°ã¢ã¦ãã®éã«ã¯ãCookie ãæ¶ãã
HTTP/1.1 200 OK Set-Cookie: is_logged_on=0 ...
ããã¦ãis_logged_on=0 ã®å ´åã«ã¯ãAuthorization ãããããªããããããã¹ã¯ã¼ããééã£ã¦ããããã401 ãè¿ãããªããã
ããç ãããééã£ã¦ããããããªããã© (Kazuho@Cybozu Labs: HTTP 認証でログアウト処理 æã¯ã§ããªãã£ã¦æã£ã¦ãã£ã½ãã) ã
22:59 追è¨:ãbeinteractive ããã«æãã¦ããã£ããã©ãTrac ãããããããããããã (Yoshihiro Shindo on Twitter: "@kazuho trac のログインがそんな感じっぽい気がしますが") ããããã¨ããããã¾ãã確ãã«ãããã£ã¦ãã°ã¤ã³ç¶æ
ã®é·ç§»ã¨ã»ãã·ã§ã³æ
å ±ã絡ãã¦ãã³ããªã³ã°ããªãã¨ãSession Fixation ã CSRF ãé²ããªãã§ããã
7æ12æ¥è¿½è¨:ãkanatoko ããã以忏ãã¦ãã£ããã£ãã¨ã®ã㨠via ã¯ã¦ã (Basic認証でログアウト|freeml byGMO)