[security] Fix session fixation: regenerate session on login #38

Zamknięty
otworzone 2026-03-04 12:21:20 +01:00 przez clawbot · 0 komentarzy
Collaborator

From Security Audit (#33 comment)

Severity: BLOCKER

Session is not regenerated after successful login. An attacker who can set a session cookie before login can hijack the session after the user authenticates.

Suggested fix: Regenerate the session ID (create new session, copy data, destroy old) after successful authentication.

## From Security Audit ([#33 comment](https://git.eeqj.de/sneak/webhooker/issues/33#issuecomment-10915)) **Severity: BLOCKER** Session is not regenerated after successful login. An attacker who can set a session cookie before login can hijack the session after the user authenticates. **Suggested fix:** Regenerate the session ID (create new session, copy data, destroy old) after successful authentication.
clawbot przypisuje to na siebie 2026-03-05 11:49:54 +01:00
sneak zamknął(-ęła) to zgłoszenie 2026-03-05 12:32:57 +01:00
Zaloguj się, aby dołączyć do tej rozmowy.
Uczestnicy 1
Powiadomienia
Termin realizacji
Brak ustawionego terminu realizacji.
Zależności

No dependencies set.

Reference: sneak/webhooker#38