Coder Social home page Coder Social logo

Better session security? about session HOT 3 CLOSED

aspnet avatar aspnet commented on May 23, 2024
Better session security?

from session.

Comments (3)

Tratcher avatar Tratcher commented on May 23, 2024

@blowdart?

from session.

blowdart avatar blowdart commented on May 23, 2024

I am about to hop on a plane, and will be slow to respond all week.

So, quickly

  1. We don't support session ID in URLs any more. So the session fixation problem goes away.
  2. As noted auth is separate to session
  3. Protecting against XSS is the app's concern, but, with MVC we encode everything by default. So, setting the cookie via XSS is unlikely, unless the developer has bypassed all our protection, at which point there's no helping them.
  4. Man in the middle attacks - use HTTPS

If you want Andre's protection then by all means add his package, but I don't see the need to implement that sort of approach ourselves.

from session.

muratg avatar muratg commented on May 23, 2024

Closing based on @blowdart's comment. @alexdresko, please let us know if you have other questions.

from session.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.