Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We use Rails CookieStore. The cookie does change when you enter sudo mode, so a session would have to be compromised while you are in sudo mode.


Ah, you are correct. It changes in the tail position, and I was only looking at the first bit. Sorry about that.

It seems impossible to ride a session in this case, as the GP suggests.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: