Attempt to spoof header (Shib-Cookie-Name) was detected
Peter Schober
peter.schober at univie.ac.at
Tue Oct 4 11:40:22 EDT 2016
* reda sabir <sabiretude at gmail.com> [2016-10-04 17:32]:
> Of course, disabling protection from cookie theft is very bad idea and
> should be avoided.An other solution would be to have a list of exceptions
> like 127.0.0.1. So is there any way to do that, or is it not developed yet?
You haven't answered my question why you don't just have both vhosts
point to the same resource (DocumentRoot or scipt or whatever) without
any proxying ("rewriting", in your own words).
That's more efficient, easier to configure and does not artificially
create cookie problems and weakened security as a result.
-peter
More information about the users
mailing list