Salesforce.com : Setting Session Security - 'Use POST requests for cross-domain sessions = true'

Information

This setting controls whether cross-domain session information is exchanged using a POST request instead of a GET request, such as when a user is using a Visualforce page. In this context, POST requests are more secure than GET requests.

Solution

Set the value of enablePostForSessions to true.

See Also

http://help.salesforce.com/help/pdfs/en/salesforce_security_impl_guide.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-2

Plugin: Salesforce.com

Control ID: 5bc8570fefce5ae377f75fbf1867625cd10cde1e70a9bc05522829554c9a8290