RubyGems Navigation menu

rack-deadline 1.0.0

rack-deadline is a simple rack middleware that automatically clears sessions that have been open too long (by default, 1 day). This is designed for use with cookie stores to mitigate the risk of session fixation, since it is impossible to invalidate older sessions with a pure cookie-based approach. It is impossible to enforce a deadline with the standard rack cookie session API. The expire_after setting is not part of the session itself (it's part of the cookie, and not cryptographically signed), and an attacker who has access to a previous cookie can just omit it when making a request. This stores a deadline inside the crytographically signed session, and once the deadline is passed, the session will no longer be valid.

Gemfile:
= クリップボードにコピー コピー完了!

インストール:
=

バージョン履歴:

  1. 1.0.1 - January 27, 2015 (7.5KB)
  2. 1.0.0 - January 28, 2014 (7.5KB)

所有者:

作者:

  • Jeremy Evans

SHA 256チェックサム:

18c91b7a6c847bcde9197a4c345d2ae7aa22f50843f34492de1b538b01a83622

累計ダウンロード数 5,645

このバージョンのみ 2,471

ライセンス:

MIT

必要なRubyのバージョン: なし

リンク: