Skip to content

Authentication is not secure #2

@dcki

Description

@dcki

The app treats all sessions as valid. There is no mechanism to expire a session (that does not depend on client-side cooperation or regenerating the Rails app secret.)

If this becomes an issue for any practical purpose, then it is time to implement real authentication (Devise or OmniAuth, maybe also Pundit).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions