Project

General

Profile

Actions

Improvements #13498

closed
MV RM

Also change session ID on logout

Improvements #13498: Also change session ID on logout

Added by Matthias Van Ceulebroeck over 1 year ago. Updated 6 months ago.

Status:
Closed
Priority:
Normal
Target version:
Start date:
02/06/2025
Due date:
% Done:

0%

Estimated time:

Description

While there is no vulnerability to resume a session that was previously logged out, due to how login state is managed. It seems clean to also change the session ID.
This is what OWASP recommends.

The Auth::Login::logout() will change the state of the Login object. This Login is unique per session, and thus identifies the session as being logged out. Any request that would then access information that ought to be guarded can recognize the state, and not allow access to controlled data.

RM Updated by Romain Mardulyn over 1 year ago Actions #1

  • Status changed from New to InProgress
  • Assignee set to Romain Mardulyn

RM Updated by Romain Mardulyn over 1 year ago Actions #2

  • Status changed from InProgress to Review
  • Assignee deleted (Romain Mardulyn)

MV Updated by Matthias Van Ceulebroeck about 1 year ago Actions #3

  • Target version changed from 4.12.0 to 4.12.3

MV Updated by Matthias Van Ceulebroeck 7 months ago Actions #4

  • Assignee set to Matthias Van Ceulebroeck

RM Updated by Romain Mardulyn 7 months ago Actions #5

  • Target version changed from 4.12.3 to 4.12.4

RM Updated by Romain Mardulyn 7 months ago Actions #6

  • Status changed from Review to Implemented @Emweb
  • Assignee changed from Matthias Van Ceulebroeck to Romain Mardulyn

RM Updated by Romain Mardulyn 6 months ago Actions #7

  • Status changed from Implemented @Emweb to Closed
  • Private changed from Yes to No
Actions

Also available in: PDF Atom