Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-14264

Improve security by regenerating session id on login

    XMLWordPrintable

Details

    Description

      For some reason the code to regenerate session id in ezsession is commented out with a comment "This doesn't seem to work as expected" probably by amos when the function was added in 3.2.

      The attached patch re enables it and properly updates the session data in db if user has a session (if user had session cookie).

      Discussion:

      1. why was it commented out? (looked up svn history in stable/3.2 and trunk, no clues)
      2. does the patch look ok?
      3. should we also implement httponly session cookies like other does?

      Attachments

        Activity

          People

            andre1 andre1
            andre1 andre1
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: