Index: openacs-4/packages/acs-core-docs/www/xml/kernel/security-design.xml =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/acs-core-docs/www/xml/kernel/security-design.xml,v diff -u -r1.5.2.2 -r1.5.2.3 --- openacs-4/packages/acs-core-docs/www/xml/kernel/security-design.xml 18 Nov 2003 15:18:36 -0000 1.5.2.2 +++ openacs-4/packages/acs-core-docs/www/xml/kernel/security-design.xml 19 Nov 2003 00:10:35 -0000 1.5.2.3 @@ -821,14 +821,14 @@ -URL sharing could be dangerous. If I happen to be browsing Amazon +URL sharing could be dangerous. If I happen to be browsing Amazon while logged in and I email a friend, he could conceivably receive it and follow it before my session has expired, gaining all of the privileges I -had. +had. -User-entered URLs are harder to handler. If a user is in the middle of +User-entered URLs are harder to handler. If a user is in the middle of a session and then types in the URL of some page, he could be kicked out of his -session. +session.