Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DWR Session ID is not changing after logging out from Application #40

Open
sam2498 opened this issue Nov 11, 2021 · 1 comment
Open

Comments

@sam2498
Copy link

sam2498 commented Nov 11, 2021

Issue : DWRsessionID is not changing when we logging out from application and then login from the same browser. This improves the chance for CSRF attack . The issue is happening in same browser window when we logout and then login , the application jsessionid is changing .

DWR Version - 3.0.2-release

@ttaruffi
Copy link

When you perform the logout, you could change the DWRSESSIONID cookie with maxAge = 0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants