Re: Security Advisory Update (XSRF issues)

On Thu, 28 Jan 2010, Chris Travers wrote:

> That isn't quite the plan.
> The sessions in 1.3 can be timed out safely at longer values (say one hour)
> and this times out form values and transaction locks for batch payments.
> If the form is submitted after that, it merely updates with a warning and
> you have to hit post again.  However the data would remain the same.  There
> is an issue with automation scripts but there are some solutions to that.

For the record, I understood your point 3 as saying what he understood it 
to be saying.

So what will actually happen, is that the form will be submitted, the user 
will be re-authenticated, and the form will be represented sans posting, 
at which point it could be resubmitted?