18F / confidential-survey

A Rails app for conducting confidential surveys without violating user privacy
Other
28 stars 6 forks source link

Explicitly disable Rails sessions #27

Closed harrisj closed 8 years ago

harrisj commented 8 years ago

Rails is only supposed to enable sessions when they are used, but I have seen them in OWASP and I want to make sure there is no way the session cookie or ANY cookie is set