Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Fix CookieStore so session.session_id returns stable value

#328

session.session_id returns the cookie value stored under _myapp_session instead of the session_id originally generated when the session was created. This causes Juggernaut (and possibly other plugins) to fail.

I modified CookieStore to store the session_id along with the session data and cryptographic signature as follows:

session_id--encoded data--signature

Reported by Rich Collins · June 4th, 2008 @ 02:08 AM

State: wontfix
Milestone: none
Assigned to: nobody
Importance: none

Activity

  1. Pratik
    Pratik
    • State changed from new to incomplete

    The patch doen't apply anymore.

    June 4th, 2008 @ 05:02 PM

  2. Rich Collins
    Rich Collins
    • State changed from incomplete to new

    How is that?

    http://github.com/rails/rails/tr...

    Still doesn't save the session_id in any way.

    June 4th, 2008 @ 10:26 PM

  3. Rich Collins
  4. Rich Collins
  5. Pratik
    Pratik
    • State changed from new to wontfix
    • Tag set to actionpack, bug, patch, tested

    How does this cause juggernaut to fail ?

    Also, this will cause all existing session cookies to be invalid. So, cannot really apply this patch as it is.

    Not sure if we really need session id when session is stored in cookies. Worth discussing in core mailing list nevertheless.

    Thanks.

    July 2nd, 2008 @ 01:46 AM

  6. blj
    blj

    This dynamic session.session_id is madness. A stable session id will be useful. Even the forgery protections are failing, which I tracked to the session.session_id being dynamic. What really is going on with this thing?

    July 6th, 2008 @ 09:45 PM

  7. blj
    blj

    I cannot get to apply any of these patches.

    July 7th, 2008 @ 10:10 AM

  8. Lourens Naudé
  9. Adam S
    Adam S

    Invalidating old implementations has never been a reason not to apply a patch to Rails in the past... the solution is to deprecate or just make the change and let plugins etc cope. This is a change that makes sense, least surprise-wise, and therefore status should not be "wont-fix", but "incomplete".

    January 15th, 2009 @ 07:32 AM

  10. Pratik
    Pratik

    Adam : Please don't take the ticket status too seriously. And the way things stand now -- "making all existing session cookies invalid" -- it is indeed 'wontfix' until we have a new patch.

    January 15th, 2009 @ 02:39 PM

  11. Adam S
    Adam S

    Umm, since I was looking for a solution to this... thought it might be useful for others.

    I've found the intermediate "fix" is to just use ActiveRecordStore (other non-cookie stores might be ok too). With cookie store session.session_id returns the myapp_session cookie, but with ActiveRecordStore (and possibly others), session.session_id is a 32 char hash which can be used for DB lookups etc...

    Before I found that out I had decided to just have a before_filter with:

    require 'uuidtools'
    session[:uuid] ||= UUID.random_create
    
    

    Either way will work fine...

    January 16th, 2009 @ 01:57 AM