[OpenStreetMap] #5027: the user's "notes" layer state should not be saved into his _osm_location cookie when he opens a link with layers=N

OpenStreetMap trac at noreply.openstreetmap.org
Tue Nov 5 13:07:19 UTC 2013


#5027: the user's "notes" layer state should not be saved into his _osm_location
cookie when he opens a link with layers=N
-------------------------+-------------------------
 Reporter:  aseerel4c26  |      Owner:  rails-dev@…
     Type:  defect       |     Status:  new
 Priority:  minor        |  Milestone:
Component:  website      |    Version:
 Keywords:  slippymap    |
-------------------------+-------------------------
 Currently, the user's state of the "notes" layer seems to be saved in the
 _osm_location cookie (an N added at the end:
 8.67995023727417%7C50.016743371076984%7C15%7CMN instead of
 8.679993152618408%7C50.01693640159293%7C15%7CM) which is valid for 10
 years per default.

 Since the state of the notes layer is (silently) changed if you open a
 layers=N link and it is saved in a long-time cookie you can infect
 (somehow) people with the notes layer. It will spread if those people send
 themselves links created with the share tool. Yeay, a semi-manual worm!
 ;-) "Notes" will rule the world soon.

-- 
Ticket URL: <https://trac.openstreetmap.org/ticket/5027>
OpenStreetMap <http://www.openstreetmap.org/>
OpenStreetMap is a free editable map of the whole world



More information about the rails-dev mailing list