Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

you put the session id inside the url params :3


But then the session id can leak via referer header :(


He was suppose to give a solution to parent's question, not necessary a secure one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: