4 ms·
Why didn't you use the classic webserver.example.edu/~$username ? Your current implementation would be a nightmare to admin in comparison
by feld 10y ago
Why didn't you use the classic webserver.example.edu/~$username ? Your current implementation would be a nightmare to admin in comparison
- charleslmunger 10y agoIsn't the same origin policy per domain? I suppose it's a security benefit that students can't xss each other.
- hdhzy 10y agoYes, exactly. At least until suborigin header [0] becomes widely supported. [0]: https://w3c.github.io/webappsec-suborigins/ https://w3c.github.io/webappsec-suborigins/
- geofft 10y agoWe originally did that, but we wanted different origins for each user, same reason GitHub uses username.github.io. Also, we wanted to support a few non-web services (we support svn://username.webhost.example.edu). Administratively, we use mod_vhost_ldap, and it hasn't been complicated. If anything it's less complicated, because a number of larger websites (departments, courses, etc.) get somename.example.edu CNAMEs from the IT department, and those are virtual hosts too. Back when we were using only webhost.example.edu/~username URLs, the separate virtual hosts were a special case. Now they're just an entry in LDAP with a different DocumentRoot, that's all.