The reason for your exclusion will certainly change the secret, while testers set cookies. Cookies are cryptographically signed using classified information that protects users from malicious files. For example, they may try to change their saved user ID to increase their privileges.
You can ask testers to clear their cookies. Or you can catch the exception and delete the cookie for your application. Some sites prefer to use ActiveRecordSession for more control over their sessions, so they drop all sessions as necessary, but at the cost of performance.
source
share