Skip to content
This repository was archived by the owner on Nov 28, 2019. It is now read-only.

Conversation

@mattjay
Copy link

@mattjay mattjay commented May 28, 2013

Wrote some skeleton auth functions that would plug in to a user model to check if authenticated before allowing to see the index.

From what I can tell the way this works is not a secure handling of cookies and is vulnerable to (at least) session fixation.

Felt like this was most of the legwork though and would love to see how you could spin this to use cookies correctly.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant