dmeese / MathWorld

Team Bunny Slippers Math World Web Application
0 stars 1 forks source link

insecure cookies #20

Open enasni opened 11 years ago

enasni commented 11 years ago

The method for creating the user session cookie is not creating secure cookies. This allows for the cookie to be modified on the client side.

Suggest using the ".signed" method when issuing client side cookies.