>>>>> "Jason" == Jason Gunthorpe <jgg@ualberta.ca> writes:

    Jason> This is also crazy. If you su to root the best thing to do
    Jason> is to set XAUTHORITY=/home/foo/.Xauthority. If you su to
    Jason> another user the sane thing to do is to use ssh and secure
    Jason> X forwarding. Otherwise you leak your X cookie to
    Jason> potentially evil users.

mod_xauth isn't this dumb; it only forwards the cookie when su'ing
from a non-root user to root (unless you configure it to do


