This project is archived and is in readonly mode.
Fix CookieStore so session.session_id returns stable value
-
Rich Collins
New patch
-
Pratik
- State changed from new to wontfix
- Tag set to actionpack, bug, patch, tested
How does this cause juggernaut to fail ?
Also, this will cause all existing session cookies to be invalid. So, cannot really apply this patch as it is.
Not sure if we really need session id when session is stored in cookies. Worth discussing in core mailing list nevertheless.
Thanks.
-
blj
This dynamic session.session_id is madness. A stable session id will be useful. Even the forgery protections are failing, which I tracked to the session.session_id being dynamic. What really is going on with this thing?
-
blj
I cannot get to apply any of these patches.
-
Lourens Naudé
-
Adam S
Invalidating old implementations has never been a reason not to apply a patch to Rails in the past... the solution is to deprecate or just make the change and let plugins etc cope. This is a change that makes sense, least surprise-wise, and therefore status should not be "wont-fix", but "incomplete".
-
Pratik
Adam : Please don't take the ticket status too seriously. And the way things stand now -- "making all existing session cookies invalid" -- it is indeed 'wontfix' until we have a new patch.
-
Adam S
Umm, since I was looking for a solution to this... thought it might be useful for others.
I've found the intermediate "fix" is to just use ActiveRecordStore (other non-cookie stores might be ok too). With cookie store session.session_id returns the myapp_session cookie, but with ActiveRecordStore (and possibly others), session.session_id is a 32 char hash which can be used for DB lookups etc...
Before I found that out I had decided to just have a before_filter with:
require 'uuidtools' session[:uuid] ||= UUID.random_createEither way will work fine...
