> Couldn't someone insert an illicit header on the browser side? If you don't use a header that your external method adequately controls. If you don't configure a header to check, it doesn't look. It's there for people with systems capable of safely utilizing it, often involving proxying where you might have tight controls over things. -- Scott