Uploaded image for project: 'DSpace'
  1. DSpace
  2. DS-330

Create new session on login / invalidate sessions on logout

    XMLWordPrintable

    Details

    • Type: New Feature
    • Status: Closed (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Fix Version/s: 1.6.0
    • Component/s: JSPUI
    • Labels:
      None
    • Attachments:
      2
    • Comments:
      2
    • Documentation Status:
      Not Required

      Description

      Reported and patched by Ekaterina Pechekhonova at NYU.

      This patch creates a new session whenever a user successfully logs in, and invalidates the session upon logout. This will reduce the possibility of session hijacking.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                stuartlewis Stuart Lewis
                Reporter:
                stuartlewis Stuart Lewis
              • Votes:
                0 Vote for this issue
                Watchers:
                0 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: