[Seaside] Session (in)security?

Boris Popov boris at deepcovelabs.com
Thu Jun 15 18:19:36 UTC 2006

Thanks, David, this works well too, I'll definitely use this together with a
session cookie just an extra layer in case anyone tries to brute-force the
session key. Its all about minimizing risk I guess, but I'm still curious
why wouldn't the cookie setting be on by default :)

Michel, attached is VisualWorks extension to Request to make it compatible
with WASessionProtector, good addition to the VW port.



DeepCove Labs Ltd.
4th floor 595 Howe Street
Vancouver, Canada V6C 2T5

boris at deepcovelabs.com


This email is intended only for the persons named in the message
header. Unless otherwise indicated, it contains information that is
private and confidential. If you have received it in error, please
notify the sender and delete the entire message including any

Thank you.

-----Original Message-----
From: seaside-bounces at lists.squeakfoundation.org
[mailto:seaside-bounces at lists.squeakfoundation.org] On Behalf Of David
Sent: Thursday, June 15, 2006 10:50 AM
To: The Squeak Enterprise Aubergines Server - general discussion.
Subject: Re: [Seaside] Session (in)security?

Boris Popov wrote:

>application preferenceAt: #useSessionCookie put: true
>Me wonders why this isn't on by default, we almost deployed with this being
You can also

    super initialize.
    self addDecoration: WASessionProtector new

in your root component.  WASessionProtector checks to make sure that
requests come from the same IP address as the original request.  Doesn't
do much good if two requests come from different users behind the same
proxy though.  I use this scheme because AFAIK there are still some
problems with session cookies....maybe they've been fixed though.


Seaside mailing list
Seaside at lists.squeakfoundation.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3370 bytes
Desc: not available
Url : http://lists.squeakfoundation.org/pipermail/seaside/attachments/20060615/a25801d8/smime.bin

More information about the Seaside mailing list