There are some other very serious security issues with cookie store as it stands now.
As I said earlier, I'm waiting for a spec and sample app before working on a full review. If those never happen, I'll eventually post the sketches that I already have. But I think the community would be happier with a material "this is how the app can be compromised" over "theoretically, depending on the implementation, this might be the problem." Anyway, if I don't here back on those things, I'll post my notes from conversation - if I do, I'll try to get a full review done. On Mar 27, 12:05 pm, "Alexey Verkhovsky" <[EMAIL PROTECTED]> wrote: > +1 to: > > CookieStore should be either (1) secure against replay > > > attacks by default, or (2) not the default session store. Anything > > else is asking too much of non-security-aware developers. --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "Ruby on Rails: Core" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [EMAIL PROTECTED] For more options, visit this group at http://groups.google.com/group/rubyonrails-core?hl=en -~----------~----~----~----~------~----~------~--~---
