4 messages in net.sourceforge.lists.courier-sqwebmailRe: [sqwebmail] Authentication from d...
FromSent OnAttachments
Szabo NandorOct 23, 2005 2:00 am 
Sam VarshavchikOct 23, 2005 7:00 am 
Szabo NandorOct 23, 2005 11:50 am 
Sam VarshavchikOct 23, 2005 2:10 pm 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:Re: [sqwebmail] Authentication from different or same IPActions...
From:Sam Varshavchik (mrs@courier-mta.com)
Date:Oct 23, 2005 7:00:33 am
List:net.sourceforge.lists.courier-sqwebmail

Szabo Nandor writes:

Helo!

I'm testing the auth part of sqwebmail.

First: try it from the same IP (example different window on the same host). Result: the latest auth is succesfull, the earlier connection is dropped.

Second: from different IP address. The result just the same : always the latest auth is succesfull.

The "sameip" variable is turned on, by default. <input type="checkbox" checked="checked" name="sameip" id="sameip">

from SECURITY file: "By default, SqWebMail permits access to the mailbox only from the same IP address as the one where the user ID and password was authenticated from."

What is the correct behavior of sqwebmail?

The behavior is correct.

The expectation by above: the latest connection should be unsuccesfull.

If you're on a modem dialup, and get bumped off, dial back immediately and get a different IP address, do you expect not being able to log in for two hours, until the earlier login session times out?