Salesforce.com : Setting Session Security - 'Use POST requests for cross-domain sessions = true'

Information

This setting controls whether cross-domain session information is exchanged using a POST request instead of a GET request, such as when a user is using a Visualforce page. In this context, POST requests are more secure than GET requests.

Solution

Set the value of enablePostForSessions to true.

See Also

http://help.salesforce.com/help/pdfs/en/salesforce_security_impl_guide.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Salesforce.com

Control ID: 33d3868fcdd8d8e796bec4c53e5d0d32c6a98a4db77d0cbc76aa8d158a4619ee