[Cosmo-dev] CMP and AJAX
travis at osafoundation.org
Tue Sep 19 12:07:38 PDT 2006
I'm currently redesigning the Cosmo administrative ui to use Spring MVC
instead of Struts. It would be nice to leverage CMP to do this, and even
to CMP so the interface could be AJAX-y.
and have run into a snag related to HTTP Basic Authentication, which is
used by CMP.
Basically, relying on the browser to do HTTP Authentication ties us into
the browser authentication popup screen, while manually doing HTTP
Authentication has some security implications we should think through.
I've put together a wiki page summarizing the problem as I see it.
could check it out and make comments, that would be great.
In general, the second option is kind of neat, and might enable a
sessionless interface, if we could make the security work. I'd be very
interested in working on it, but don't want to start without getting
More information about the cosmo-dev