3 ms·
For stateless load balancing without a central server. By having the data in a client cookie so that any web server can access it. Without it you need sticky se
by sehrope 13y ago
For stateless load balancing without a central server. By having the data in a client cookie so that any web server can access it. Without it you need sticky sessions on your load balancer or a central data store requiring additional round trips for each request. A lot of frame works use the same principle (ex: Django uses it too).
The data stored in the cookie is cryptographically signed with the secret token so the server can verify if its been tampered with. It's a very solid approach but like anything involving crypto it's important to keep the secrets secret!
To clarify, the secret token should only be known to the server. The client doesn't have it. The client only has their own signed cookie data.
- stephenr 13y agoSo you're telling me the official rails policy is: we think you (developers) are smart enough to build an app that works on a distributed cluster but aren't smart enough to work out how to use a central/replicated system for session storage. At the very least cookie storage should be an opt-in for apps that need it, not a default with apparently not enough warnings about the security aspects