[Openstack-security] Fwd: [Full-disclosure] [Django] Cookie-based session storage session invalidation issue

Jacob Kaplan-Moss jacob at djangoproject.com
Fri Oct 4 03:51:14 UTC 2013


On Thu, Oct 3, 2013 at 10:48 PM, Kurt Seifried <kseifried at redhat.com> wrote:

> My one comment would be to possibly make the reply warning more
>  prominent and also mention protecting the cookie with HTTPS (wireless
> networks in coffee shops/etc.).


That's a good idea; we talk about cookie security and HTTPS elsewhere, but
it's probably worth re-mentioning right there, too. Thanks for the
suggestion!

Jacob
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-security/attachments/20131003/7ed867f1/attachment.html>


More information about the Openstack-security mailing list