Coffee on the Keyboard
  • Home
  • jamessocol.com
Sign in Subscribe

sessions

A collection of 1 post
django

Session Fixation and Hijacking - Basic Security Part 6

NB: This is the sixth post in a series [https://www.coffeeonthekeyboard.com/best-basic-security-practices-especially-with-django-697/] of posts on web application security. 1. Don’t put session IDs in the URL. Django explicitly does not support [https://docs.djangoproject.com/en/dev/topics/http/sessions/#session-ids-in-urls] this because it’s just dangerous.
24 Jul 2012 2 min read
Page 1 of 1
Coffee on the Keyboard © 2025
Powered by Ghost