<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>aC forum: How do I lock it down so only logged in users can view projects etc?</title>
  <link>http://www.activecollab.com/forums/topic/1837/</link>
  <description>Recent posts on topic: How do I lock it down so only logged in users can view projects etc?</description>
  <dc:language>en-us</dc:language>
  <pubDate>Sat, 30 Aug 2008 02:37:14 UTC</pubDate>
  
  <item>
    <link>http://www.activecollab.com/forums/post/8562/#post8562</link>
    <guid>http://www.activecollab.com/forums/post/8562/#post8562</guid>
    <title>Post #7 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>Yes - the same way as someone needs a copy of your password to access the entire system :)<br />
<br />
Token is generated randomly per user, it is changed every time user changes the password and RSS and iCal URL-s are generated for logged in user only. If you don't trust the system that everyone is using without any problems you can alter FeedController and make all actions unusable.</p>]]></description>
    <pubDate>Sun, 02 Sep 2007 06:06:21 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8561/#post8561</link>
    <guid>http://www.activecollab.com/forums/post/8561/#post8561</guid>
    <title>Post #6 by DanielX</title>
    <dc:creator>DanielX</dc:creator>
    <description><![CDATA[<p>so does that mean that all anyone needs to hav access is to hav a copy of the rss link?</p>]]></description>
    <pubDate>Sun, 02 Sep 2007 00:19:21 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8541/#post8541</link>
    <guid>http://www.activecollab.com/forums/post/8541/#post8541</guid>
    <title>Post #5 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>That is because authentication data is included in the URL. <br />
<br />
Try to remove token variable from the URL, copy it to Opera and than try to login. Now try to guess your token.</p>]]></description>
    <pubDate>Fri, 31 Aug 2007 06:05:14 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8535/#post8535</link>
    <guid>http://www.activecollab.com/forums/post/8535/#post8535</guid>
    <title>Post #4 by DanielX</title>
    <dc:creator>DanielX</dc:creator>
    <description><![CDATA[<p>That's reassuring - but i was able to copy the rss link to the Opera browser and it didnt ask me to log in, it just gave me direct access.</p>]]></description>
    <pubDate>Thu, 30 Aug 2007 20:38:58 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8532/#post8532</link>
    <guid>http://www.activecollab.com/forums/post/8532/#post8532</guid>
    <title>Post #3 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>RSS links are protected with tokens so it is not true that anyone can access them.<br />
<br />
Also, RSS is read-only technology. You cannot use RSS to alter or delete anything in activeCollab.<br />
<br />
Have fun! :)</p>]]></description>
    <pubDate>Thu, 30 Aug 2007 05:38:19 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8529/#post8529</link>
    <guid>http://www.activecollab.com/forums/post/8529/#post8529</guid>
    <title>Post #2 by DanielX</title>
    <dc:creator>DanielX</dc:creator>
    <description><![CDATA[<p>Also how do i take out the RSS links?</p>]]></description>
    <pubDate>Thu, 30 Aug 2007 00:35:28 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/8528/#post8528</link>
    <guid>http://www.activecollab.com/forums/post/8528/#post8528</guid>
    <title>Post #1 by DanielX</title>
    <dc:creator>DanielX</dc:creator>
    <description><![CDATA[<p>It seems anyone on the net can view what they like and add what they like anonymously... especially thru the RSS feed.<br />
<br />
<br />
As I dont want outsiders ear-winging on clients etc, how do I make sure only account holders can get in?</p>]]></description>
    <pubDate>Thu, 30 Aug 2007 00:27:17 UTC</pubDate>
  </item>
</channel>
</rss>