Uploaded image for project: 'jUDDI (Retired)'
  1. jUDDI (Retired)
  2. JUDDI-559

Authentication Tokens do not expire

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 3.1.4
    • 3.1.5
    • None

    Description

      This is a potential security vulnerability. Tokens issued by the Security API do not expire. This increases the chances if a token could be obtained through a man in the middle attack or through session hijacking that the stolen token could be used to impersonate the user.

      Suggestion, assign expiration timestamps to tokens that is administrator configurable. Default setting should be about 15 minutes.

      Attachments

        1. revised Expiration patch.patch
          8 kB
          Alex O'Ree
        2. ExpiringAuthTokens.patch
          16 kB
          Alex O'Ree

        Activity

          People

            kstam Kurt Stam
            spyhunter99 Alex O'Ree
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: