<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Recent Posts in Password shown in url | Unfuddle Community</title>
    <link>http://unfuddle.com/community</link>
    <description>Unfuddle Community Forums</description>
    <item>
      <guid isPermaLink="false">www.unfuddle.com/community:3:967:2757</guid>
      <title>Password shown in url posted by kleinmp @ Wed, 18 Aug 2010 22:10:17 UTC</title>
      <link>http://www.unfuddle.com/community/forums/3/topics/967</link>
      <description>When I login with the ajax login form, I noticed that from that point on, my urls contain both my username and password in plaintext. 
ie https://my-site.unfuddle.com/...?ajax_username=my-username&amp;ajax_password=my-password.

That isn't very secure.  This only happens when my session expires while I'm working in unfuddle and the ajax popup comes up.</description>
      <pubDate>Wed, 18 Aug 2010 22:10:17 UTC</pubDate>
      <author>kleinmp</author>
    </item>
    <item>
      <guid isPermaLink="false">www.unfuddle.com/community:3:967:2758</guid>
      <title>Password shown in url replied by David C. @ Wed, 18 Aug 2010 23:30:14 UTC</title>
      <link>http://www.unfuddle.com/community/forums/3/topics/967</link>
      <description>Kleinmp,

You are right. This is insecure and completely unacceptable.

This issue was the unfortunate result of a very recent (within the last 24 hours) deploy. Please note that the issue only persisted for a few hours earlier today and has since been fixed.

If you have not done so already, please clear your cache and reload Unfuddle in your browser to make sure you have the updated interface.

I apologize for the inconvenience.</description>
      <pubDate>Wed, 18 Aug 2010 23:30:14 UTC</pubDate>
      <author>David C.</author>
    </item>
  </channel>
</rss>

