K

Encode login status in session cookie

  • Thread starter Thread starter Kirby
  • Start date Start date

Visitor Greeting

Welcome to NullWarehouse.com... We are currently seeking Mod's and Contributors. If you wish to apply for a Mod position then please click on Members dropdown arrow, then click on Staff App and fill it out completely and submit it. If you want to be a Contributor then start contributing and we will have our eye on you and take notice, something great could come of it.

  • We have redone the forum. If you notice any issues or errors please open a Support Ticket under the Members dropdown and let us know.
K

Kirby

Guest

Right now it is not possible to distinguish a logged in user from a guest by just looking at the session cookie - if both cases it's just a random string.

Being able to distinguish a guest from a logged in user on the webserver level (or a reverse proxy in front of that) could be quite useful for applying different rules (like rate limits, challenges, etc.) partly based on the login status.

I therefore suggest to add a flag to the session cookie value (for example a prefix...

Read more

Continue reading...
 
Similar content Most view View more
Back
Top Bottom