Skip to content

Include client IP address in encrypted cookie #838

Open
@jlouvel

Description

@jlouvel

Based on this discussion, it seems useful to include the client IP address in the encrypted cookie to prevent replay attacks from other clients who stole the cookie.
http://restlet.tigris.org/ds/viewMessage.do?dsForumId=4447&dsMessageId=3060350

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions