Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Authentication for every action - cookie can be stealed and reused if browser it is not closed. #105

Open
rapi3 opened this issue Jan 27, 2019 · 0 comments

Comments

@rapi3
Copy link

rapi3 commented Jan 27, 2019

Hi,
I notice that even after RPI reboot if browser it is not closed and cookie destroyed the authentication cookie can be re/used forever... this open the problem with cookie stealing.
Is it possible to set on controller to request authentication for every action ?
Normally the credentials are saved in browser by user so there is no need to reenter every time just to confirm them.
This behavior will protect also for unwanted action if tap by mistake on phone when scrolling the page looking in a long list.... I have 16 relays ( and I plan to add 8 more ) all used for: heating, lights, doors, power plug control... and old eyes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant