3 ms·
the sid is inaccessible to js running in another domain context, so anamax is pointing that it suffices to just retransmit the sid as one of the request paramet
by jeremyawon 17y ago
the sid is inaccessible to js running in another domain context, so anamax is pointing that it suffices to just retransmit the sid as one of the request parameters, rather than generating and including sig=hash(request+sid).
you're right that the remotely invoked request will include the sid as part of the http cookies header - it's what goes into the get/post request parameters which differentiates the domain context of the invoker. and if someone can't generate and include a sig because they can't access the sid, then the challenge might as well just be including the sid.
the only draw back i see is that i wouldn't have had an excuse to learn how to implement sha ;)
*edit: jim_lawless points out below that you might not want a sid showing up in web server logs. my system frequently rotates the clients sid, so it's not a concern to me - but if you do use less transient sid cookies you might want to implement the hash signature approach after all?