Skip to content

Session regen's, and lifespan's #1

@circuitbomb

Description

@circuitbomb

The user session needs to be regenerated at login and if the user-agent changes during a session.
Also passwords shouldnt be stored session side, even with a salt, perhaps use another unique string in place (md5(mt_rand()))
Also session lifetime should be set:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions