The option "Only allow a session id to be propagated using URL parameters if HTTP authentication was used" doesn't work correctly, it blocks requests with session id in query string for HTTP authentication as well in some cases.

Comments

decafdennis’s picture

Status: Active » Closed (fixed)

Option is now gone anyway.