andrewshilliday / garage-door-controller

Software to monitor and control garage doors via a raspberry pi
MIT License
327 stars 132 forks source link

Authentication for every action - cookie can be stealed and reused if browser it is not closed. #105

Open rapi3 opened 5 years ago

rapi3 commented 5 years ago

Hi, I notice that even after RPI reboot if browser it is not closed and cookie destroyed the authentication cookie can be re/used forever... this open the problem with cookie stealing. Is it possible to set on controller to request authentication for every action ? Normally the credentials are saved in browser by user so there is no need to reenter every time just to confirm them. This behavior will protect also for unwanted action if tap by mistake on phone when scrolling the page looking in a long list.... I have 16 relays ( and I plan to add 8 more ) all used for: heating, lights, doors, power plug control... and old eyes.