OWASP Consider Restoring a New Session after Authentication or Privilege Level Success

One of the top ten points on the OWASP website claims that we should consider restoring a new session if the authentication level or privilege is successfully changed.

What would be the right way to do this?

One thing that the employee told me about, but I didn’t test, is that when a user uses browser tabs, each tab does not receive its own session, so I think this negates the whole exercise.

Thanks Paul Sperantza

+3
source share
1 answer

, , - session.invalidate(), , .

+1

Source: https://habr.com/ru/post/1712465/


All Articles