4 ms·
We were seeing some pages with cookies incorrectly getting cached, causing users to get logged in as other users. We quickly disabled cache on the dashboard, is
by tikotzky 4y ago
We were seeing some pages with cookies incorrectly getting cached, causing users to get logged in as other users. We quickly disabled cache on the dashboard, is this related to that?
- bcjordan 4y agoCurious what you find happened with that. On the webdev side—what can be done as extra defense-in-depth step to guard against this kind of issue? Unrelated to Cloudflare I feel like it is a common issue that crops up on even massive sites quite often. Is there some sort of secondary check / content decryption that could be required on the client-side to contain session cookie crossover?
- rob-olmos 4y agoOutside of HTTPS, typically it would be tying the session cookie to the IP address or netblock but because it's Cloudflare IPs, for regular browser navigation requests I don't think there's anything that can be done?
- jgrahamc 4y agoPlease email me details (jgc).