-
Notifications
You must be signed in to change notification settings - Fork 139
Description
#94 allows to have dss to not reload the page when the session expires.
This can leave sensible data on the screen for a hacker to right click -> inspect -> delete whatever blocks the view or leave sensible data in memory that a hacker could obtain remotely.
However, it delivers a lot better user experience, particularly when the page has taken steps to setup.
I wonder how many of you are running a fork of the script that doesn't reload the page ?
I would really like this to become the default, in this case, would it be necessary for you that sensible data be encrypted during the time the session is locked if the page isn't reloaded to a blank login script as it is today ?
I'm asking "you" for everybody reading this, I haven't had this script in production for ages, if anybody wants to step up as a maintainer it's a golden opportunity that will make you learn things in life that you could not learn in any other way !