This project is archived and is in readonly mode.
ActiveRecord::SessionStore allows blank session_id
-
Yehuda Katz (wycats)
- State changed from new to incomplete
- Tag set to question
- Assigned user set to Yehuda Katz (wycats)
- Milestone cleared.
What's the case where the user unintentionally passes in an empty session ID?
-
phan
If the user unintentionally pass in a empty session ID, I would think, we'd have to generate one for them. Otherwise if two users * unintentionally* passing empty session ids, they are gonna share a session object therefore a security risk.
-
Dan Pickett
- Tag changed from question to bugmash, question
Can someone write a failing test case to verify this behavior? Patches welcome as well, of course!
-
Anil Wadghule
not reproducible
I have added following lines in session_store.rb
Rails.application.config.session_store :active_record_store, :cookie_only => false, :key => nil
Attached is a rails app showing it is not reproducible. Hit multiple requests to http://localhost:3000/ (with multiple browsers). It never adds a record with session_id as nil / blank.
-
Rust/OGAWA
Attached patch is a test which should fail : a blank session_id is allowed.
-
Rust/OGAWA
Above patch is for 2-3-stable.
-
Rust/OGAWA
In ActionController::Session::AbstractStore, session_id is regenerated if it is nil. However, session_id is null string(""), it is not regenereted.
Threfore, if session_id is null string, AbstractStore runs the code like ActionController::Request#reset_session and regenerates session_id. And ActionController::Session::AbstractStore#load_session treats correctly if request.cookies[@key] is blank.
This patch for 2-3-stable is attached.
