4 ms·
Yeah. There was a discussion about it in an earlier thread. Unfortunately, I can't seem to find it anymore. If you look at the code, the session store is sto
by qaexl 19y ago
Yeah. There was a discussion about it in an earlier thread.
Unfortunately, I can't seem to find it anymore.
If you look at the code, the session store is stored in plaintext with the hash. Rails rehashes the plaintext in the cookie and checks it against the hash to make sure it has not been tampered with. The last time I checked, the hashing uses OpenSSL's HMAC hashing rather than the SHA1 in earlier versions of Rails.
You, as the developer, are responsible for entering in the site's secret code. It should be possible to write a Rails 2.0 initializer in config/intializer to check the presence of config/secret.yml and if not, generate it in runtime. This keeps you from having to save the secret in the version control, but unfortunately, doesn't work well when you deploy it across several machines.
Note that the cookie store was available in 1.2. Seems as if the core developers like it enough to enable it by default. As for me, I think I'll stick with ActiveStore for a while until my sites needs more drastic means, such as memcached or even cookie store.
- carpal 19y agoHeres the thread: http://news.ycombinator.com/item?id=81932 http://news.ycombinator.com/item?id=81932