what is the vulnerability of having Jsessionid on first request only

后端 未结 3 1509
半阙折子戏
半阙折子戏 2020-12-16 07:24

Recently we removed jsessionid from URL did cookies based session management to prevent \"session hijacking attack\"

But we found that first request URL always has

3条回答
  •  甜味超标
    2020-12-16 07:56

    did cookies based session management to prevent "session hijacking attack"

    Whats stopping the cookie being hijacked?

    Session managment is a server side thing - You need to server to check (based on the cookie) that the user is meant to be logged in.

    I don't think you've improved security here at all to be honest, take a look at this excellent article to see why.

提交回复
热议问题