1
Quote:
If you are checking the HTTP REFERER (which XOOPS does by default) you are quite safe from the malicious attacks where your site admins are tricked into performing actions on your site by submitting forms on another site. However, checking the HTTP REFERER is not entirely friendly towards your users, who may have to configure their firewall for your site. The token system makes your site less vulnerable should you decide to disable the referer checking.
So, my question is, how do you disable referer checking?
Because I know that when you send a PM, it check referers, and I want that disabled since some users may have firewalls to block referers.