4 ms·
Thank you! What happened out of curiosity?
by ehPReth 4y ago
Thank you! What happened out of curiosity?
- outworlder 4y agoDoubtful anyone would post anything here before there's time to write a proper RCA.
- jgrahamc 4y agoTeam is writing it up. Will get it out later today.
- tikotzky 4y agoWe were seeing some pages with cookies incorrectly getting cached, causing users to get logged in as other users. We quickly disabled cache on the dashboard, is this related to that?
- bcjordan 4y agoCurious what you find happened with that. On the webdev side—what can be done as extra defense-in-depth step to guard against this kind of issue? Unrelated to Cloudflare I feel like it is a common issue that crops up on even massive sites quite often. Is there some sort of secondary check / content decryption that could be required on the client-side to contain session cookie crossover?
- rob-olmos 4y agoOutside of HTTPS, typically it would be tying the session cookie to the IP address or netblock but because it's Cloudflare IPs, for regular browser navigation requests I don't think there's anything that can be done?
- jgrahamc 4y agoPlease email me details (jgc).
- ehPReth 4y agoAwesome - thanks :)