Uploaded image for project: 'CXF-Fediz'
  1. CXF-Fediz
  2. FEDIZ-152

Disable URL rewrites with SessionID to avoid session hijacking

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 1.3.0, 1.2.2
    • IDP, OIDC
    • None

    Description

      if Cookies are disabled within the Browser the servlet container (like Tomcat) will usually switch to URL rewriting, by adding the JSessionID to the URL.
      This is dangerous because users tend to copy URLs from their browser and post them in chat or public forums, thus allowing someone else to hijack their session.

      Therefor it is best practice to ensure that a sessionID will not be included within the URL.

      Attachments

        Activity

          People

            jan4talend Jan Bernhardt
            jan4talend Jan Bernhardt
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: