Announcement

Collapse
No announcement yet.

Release 6.20.0: The property com.openexchange.cookie.hash has been added

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Release 6.20.0: The property com.openexchange.cookie.hash has been added

    The property com.openexchange.cookie.hash is added to the configuration file server.properties. It configures if the hash for the cookie validation is calculcated on every request or simply remembered in the session object. Calculating the hash value is more secure because changes in the User-Agent HTTP header lead to a session invalidation. Those changes are ignored if the hash is used from the session.

    Possible side effects of the hash calculation on every request may be more frequent session invalidation. If that takes place switch the property to remember the hash in the session.
Working...
X