<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>aC forum: RSS not protected?</title>
  <link>http://www.activecollab.com/forums/topic/1795/</link>
  <description>Recent posts on topic: RSS not protected?</description>
  <dc:language>en-us</dc:language>
  <pubDate>Fri, 29 Aug 2008 01:34:21 CDT</pubDate>
  
  <item>
    <link>http://www.activecollab.com/forums/post/8369/#post8369</link>
    <guid>http://www.activecollab.com/forums/post/8369/#post8369</guid>
    <title>Post #5 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>Yeah, visit to RSS feed with a proper token will create a new session for you. <br />
<br />
We fixed that problem in activeCollab 1.0. Logging in with token gives you access only for that request.</p>]]></description>
    <pubDate>Tue, 07 Aug 2007 05:58:55 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8368/#post8368</link>
    <guid>http://www.activecollab.com/forums/post/8368/#post8368</guid>
    <title>Post #4 by WhiskI</title>
    <dc:creator>WhiskI</dc:creator>
    <description><![CDATA[<p>The problem is maybe on the other side - checking RSS made me automaticaly logged and via web browser I don't need to login!<br />
So as far as my RSS reader is running, anybody at my computer has my (admin) rights without need to login to AC :(<br />
It's not a big problem, but I want to warn...<br />
(sorry for anglisch :)</p>]]></description>
    <pubDate>Tue, 07 Aug 2007 05:55:39 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8367/#post8367</link>
    <guid>http://www.activecollab.com/forums/post/8367/#post8367</guid>
    <title>Post #3 by suntrop</title>
    <dc:creator>suntrop</dc:creator>
    <description><![CDATA[<p>Ok, thanks for your answer. I didn't know that :-)</p>]]></description>
    <pubDate>Tue, 07 Aug 2007 03:10:35 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8360/#post8360</link>
    <guid>http://www.activecollab.com/forums/post/8360/#post8360</guid>
    <title>Post #2 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>RSS is protected with a password based token that is used to authenticate user and serve only the data he or she can see. <br />
<br />
To see what I am talking about try to access RSS feed without knowing that weird 40 letters long parameter in the URL.</p>]]></description>
    <pubDate>Fri, 03 Aug 2007 09:04:35 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8359/#post8359</link>
    <guid>http://www.activecollab.com/forums/post/8359/#post8359</guid>
    <title>Post #1 by suntrop</title>
    <dc:creator>suntrop</dc:creator>
    <description><![CDATA[<p>Hi,<br />
<br />
I've noticed that the RSS Feed isn't password protected so anybody on the web could actually see what is going on and what I have done. Maybe this is good for some reasons and customers can see the latest changes, but not for me and my company. Is there a chance to stop the RSS Feed or is it planned to protect this?<br />
<br />
<br />
Thanks for your answer.<br />
<br />
regards<br />
- Sebastian -</p>]]></description>
    <pubDate>Fri, 03 Aug 2007 08:59:04 CDT</pubDate>
  </item>
</channel>
</rss>