gavincarr / mod_auth_tkt

Lightweight single-signon authentication module for Apache
Other
37 stars 22 forks source link

[PROPOSAL] Include the User-Agent alongside the IP address #26

Open fancsali opened 3 years ago

fancsali commented 3 years ago

For an additional layer of security the cookie hash could include the User-Agent, so to have a bit more confidence, it's the same browser using the cookie, that has been authenticated in the first place.