Knowledgebase

Managing Sessions Securely Print

  • phplaravel, security, woocommerce, domainrenewal, password, guide, howto, solution
  • 0

Keeping people signed in.

WHAT A SESSION IS

Data associated with a visitor across requests, identified by a cookie.

WHAT TO CONFIGURE

Cookies marked secure, so they travel only over encrypted connections Cookies inaccessible to scripts Restriction on cross-site sending A sensible expiry

WHAT TO DO ON SIGN-IN

Regenerate the session identifier.

WHY

It prevents an attacker who supplied an identifier beforehand from using it.

WHAT TO DO ON SIGN-OUT

Destroy the session entirely, not only clear its contents.

WHAT TO DO ON PASSWORD CHANGE

Invalidate other sessions.

WHAT NOT TO STORE IN A SESSION

More than is needed Anything sensitive that could be held elsewhere

WHAT TO CONSIDER

Where sessions are stored, and whether that scales.

WHAT TO SET

An idle timeout, appropriate to the sensitivity of the application.

WHAT TO PROVIDE

A way for a person to see and end their other sessions, in a sensitive application.

WHAT TO TEST

That signing out genuinely prevents further access.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot