What data should never be included in a session?

What data should never be stored in a session?

+3
source share
9 answers

I am very sorry that it was clear what session you mean. Depending on the answer, I can come up with a couple:

  • Passwords of any type
  • Large amounts of data, especially 4 GB + on a 32-bit OS (guaranteed memory if it should be loaded into RAM)
  • Executable code
  • Raw SQL
  • Abusive words
  • Things that may provoke indignation of government agencies ("Free Tibet" in China, threats to the president in the USA)
  • PIN of your bank account or credit card number
  • Mad Badger. Actually, ANY kind of badger.
+7

, . , -. , , . HTTP , - , , .

+4

PHP.

$_SESSION, , cookie.

.

, .

+2

. , , . , . , , .. ( InProc), . , .

, , , , , , ViewState . - , , , . , ViewState, QueryString .. .

+1

session session !

+1

- , SessionMode="InProc" web.config. - .

, - , SessionMode. , ( , ), .

0
  • DataSets: , ( 1 20 /, ).
  • : ( ) , ASP.NET , .

See the Tess Ferrandes blog for other examples of things you should never put in a session, as well as the reasons why.

0
source

Promotions, pirated CDs, feature films (other than Clerks, this movie was awesome), analogue information, ...

This question seems a little vague - I can come up with countless kinds of information that should not be stored in the session!

0
source

Source: https://habr.com/ru/post/1730946/


All Articles