Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Revert "fix: remove sessionId from URLs" #2533

Merged
merged 1 commit into from
Dec 5, 2023

Conversation

DafyddLlyr
Copy link
Contributor

@DafyddLlyr DafyddLlyr commented Dec 4, 2023

Reverts #2485

From Jumpsec -

Regarding the issue with a session value being contained within GET parameters, I believe this should be fine and I have removed it from the findings (due to an email address being required for further authorisation).

Reverting this restores the allowResumeOnBrowserRefresh() functionality which I didn't really have a decent / simple fix in mind for 👍

Related change #2494 is good to stay in place as this is still a valid alternate method of grabbing the sessionId value.

@DafyddLlyr DafyddLlyr requested a review from a team December 4, 2023 17:25
Copy link

github-actions bot commented Dec 4, 2023

Removed vultr server and associated DNS entries

Copy link
Member

@jessicamcinchak jessicamcinchak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Really pleased this is safe to stay - thanks for following up with Jumpsec about it!! Was realising how much I rely on resuming on refresh or being able to quickly grab id from URL when testing submissions yesterday 🙂

@DafyddLlyr
Copy link
Contributor Author

Was realising how much I rely on resuming on refresh or being able to quickly grab id from URL when testing submissions yesterday

I know right - me too. Hit this so many times in just a few days, really pleased to revert it.

@DafyddLlyr DafyddLlyr merged commit 5131700 into main Dec 5, 2023
12 checks passed
@DafyddLlyr DafyddLlyr deleted the revert-2485-mh/remove-session-id-from-urls branch December 5, 2023 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants