Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bind the session id to the ip address #243

Open
RKrahl opened this issue Sep 8, 2020 · 0 comments
Open

Bind the session id to the ip address #243

RKrahl opened this issue Sep 8, 2020 · 0 comments

Comments

@RKrahl
Copy link
Member

RKrahl commented Sep 8, 2020

It would improve security if the session id in ICAT would be bound to the ip address that the login request came from. E.g. on login, the ip address would be registered alongside the user name. For each subsequent request using this session id, the session id would be considered invalid if the ip address of the request does not match the registered one.

This would protect against hijacking the session in the case that the session id has been disclosed to an attacker.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant