3 ms·
You are absolutely right here. I guess I want to point out that I was not wrong but simply vague (I guess I need to have a bit more peer review on these things)
by adam_baldwin 17y ago
You are absolutely right here. I guess I want to point out that I was not wrong but simply vague (I guess I need to have a bit more peer review on these things). I never said to put it in the cookie, I did say session (I meant server side).
- sunir 17y agoJust to be clear to the readers, putting the token in the session has the same vulnerability. If you're going to use a token, put it in the form.