KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
For my app I'm implementing the same security as shown in the zentask. public class Secured extends Authenticator { @Override public String getUsername(Context ctx) { return ctx.session().get("email"); } @Override public Result onUnauthorized(Context ctx) { ctx.flash().put("error", "please login to proceed"); return redirect(routes.Application.index()); } } When a user is authenticated isuser session().put("email", email) ; I have two problems. First: how you invalidate a session when user leaves the app without using the logout? Second more serious one is that I examined the cookie using firefox plugin cookies manager+ and I can copy a cookie and later paste it thus I can access methods without having to first login, basically I can steal sessions
Tags (comma-separated)
Save Edits
Cancel