This project is archived and is in readonly mode.
Unneccessary session loading/creation in form_authenticity_token
-
foospam (at o2)
+1 for me. I'm using ActiveRecord session store and my db would be gratefull to see less session related hits.
-
Matthew Beale
Also, ActiveSupport::SecureRandom.base64(32) is spitting out strings with spaces in them. The spaces are converted to + in params manipulation so there are intermittent InvalidAuthTokens.
Have you guys seen this?
-
coffeeaddict_nl
+1 for me 2! I have seen the intermittent InvalidAuthToken messages (mainly IE6). { Still can't figure out why Rails still uses base64 when hex is also available on the same module }
I am all for the proposed method of using hmac for the authenticitytoken as it will prevent those errors and seems more secure then the current random value, but I fail to see how one can protect the session store against DoS with it if you need a session ID.
If an antagonist where to make 1000 fresh requests, you will have 1000 sessions created. In a DDoS that will swamp your mysql server in no time - seems like a non fix on that end 2 me
-
Santiago Pastorino
- State changed from new to open
- Importance changed from to
This issue has been automatically marked as stale because it has not been commented on for at least three months.
The resources of the Rails core team are limited, and so we are asking for your help. If you can still reproduce this error on the 3-0-stable branch or on master, please reply with all of the information you have about it and add "[state:open]" to your comment. This will reopen the ticket for review. Likewise, if you feel that this is a very important feature for Rails to include, please reply with your explanation so we can consider it.
Thank you for all your contributions, and we hope you will understand this step to focus our efforts where they are most helpful.
-
Santiago Pastorino
- State changed from open to stale