Fixed a sentence in the session security docs; thanks claudep.
This commit is contained in:
parent
e6800ea136
commit
4d27d311f6
|
@ -655,8 +655,8 @@ Session security
|
||||||
================
|
================
|
||||||
|
|
||||||
Subdomains within a site are able to set cookies on the client for the whole
|
Subdomains within a site are able to set cookies on the client for the whole
|
||||||
domain. This makes session fixation possible if all subdomains are not
|
domain. This makes session fixation possible if cookies are permitted from
|
||||||
controlled by trusted users (or, are at least unable to set cookies).
|
subdomains not controlled by trusted users.
|
||||||
|
|
||||||
For example, an attacker could log into ``good.example.com`` and get a valid
|
For example, an attacker could log into ``good.example.com`` and get a valid
|
||||||
session for their account. If the attacker has control over ``bad.example.com``,
|
session for their account. If the attacker has control over ``bad.example.com``,
|
||||||
|
|
Loading…
Reference in New Issue