Revert r76077, r76079, they were an overreaction to a security bug that wasn't really...
authorRoan Kattouw <catrope@users.mediawiki.org>
Fri, 5 Nov 2010 11:54:35 +0000 (11:54 +0000)
committerRoan Kattouw <catrope@users.mediawiki.org>
Fri, 5 Nov 2010 11:54:35 +0000 (11:54 +0000)
commit79b4e0fdd86aec4226743f79faf65195d5ad2268
treee36175f4d5f84835aecc7972883fcba12191fc35
parentb8095a89d2b2b4b8268a5e289f3e372937660315
Revert r76077, r76079, they were an overreaction to a security bug that wasn't really a security issue at all. The API will currently echo your session cookie back at you, but an attacker can only read that output using same-domain AJAX, and if they can do that they can do worse things (and steal the user's session in easier ways).
RELEASE-NOTES
includes/api/ApiLogin.php