Uploaded image for project: 'Wave'
  1. Wave
  2. WAVE-133

Security: We need to generate a new session id when user logs in.

Add voteWatch issue
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Minor
    • Resolution: Unresolved
    • None
    • None
    • Server

    Description

      We are should generate a new session see code here:
      http://code.google.com/p/wave-protocol/source/browse/src/org/waveprotocol/box/server/rpc/AuthenticationServlet.java#127

      This can be a security vulnerability.


      Issue imported from http://code.google.com/p/wave-protocol/issues/detail?id=132

      Owner: so...@google.com
      Label: Type-Defect
      Label: Priority-Medium
      Stars: 1
      State: open
      Status: Accepted

      Attachments

        Activity

          People

            Unassigned Unassigned
            Anonymous Anonymous

            Dates

              Created:
              Updated:

              Slack

                Issue deployment