3 ms·
Misleading. It's not a problem of CookieStore or Rails, it's the problem of HTTP. Changing session store to a database or memory store won't fix it: a session i
by luikore 13y ago
Misleading. It's not a problem of CookieStore or Rails, it's the problem of HTTP. Changing session store to a database or memory store won't fix it: a session id is still required on the client side, then your session is still hijacked because the attacker still gets the session id. You may want to make the session id change after each request, then you are re-inventing TCP and ruining user experience. If the attacker can steal CookieStore, that means the attacker can also see everything else in the page, just securing the session does little help -- please stop worrying and use HTTPS (and add "secure" option for the cookie entry).
CookieStore does its own job correctly: it has an "httponly" option which prevents being stolen by injected javascript, and it checks signature which prevents content being modified or forged. But it's not CookieStore's job to prevent sensitive content being watched. It's HTTPS's job.
- damncabbage 13y agoChanging session store to a database or memory store won't fix it: a session id is still required on the client side, then your session is still hijacked because the attacker still gets the session id. The bug specifically addresses logging out. When you store a record of the session on the server side (with the session ID you mention), you clear that session record during logout; the session is now gone, and cookie isn't valid anymore. (With the cookie-only approach, the server will continue to accept a cookie that you wanted to have cleared.)
- luikore 13y agoWhen I click log out, I know I'm logging out on this browser but not other browsers. I usually want to keep my session on other devices... But you can still achieve "log me out on every devices" with CookieStore, it doesn't limit you from storing and checking things on the server-side.
- damncabbage 13y agoWhen I click log out, I know I'm logging out on this browser but not other browsers. Different browsers get different sessions. ... it doesn't limit you from storing and checking things on the server-side. Correct, but you basically end up reimplementing parts of ActiveRecord::SessionStore anyway.
- smrtinsert 13y agoGot it, filing a bug at HTTPs github page. On a more serious note, this is why we have frameworks, and dont let developers roll their own because its "super easy".