Collected research
Ruby on Rails Session Termination Design Flaw
MaverickBlogging | technology & art by G. S. McNamara
Rails' default CookieStore holds the whole session in the client cookie, so no server-side record exists to delete at logout. Logging out only issues a replacement cookie and the old one stays valid indefinitely, letting anyone holding a captured cookie re-authenticate later. Rails 2.0 to 4.0 are affected and Rails 4's cookie encryption does not fix it; ActiveRecordStore does.
Record
- Document
- MaverickBlogging | technology & art by G. S. McNamara
- Researcher
- G. S. McNamara
- Published by
- maverickblogging.com
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of G. S. McNamara, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .