Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
bgdam
on Dec 27, 2012
|
parent
|
context
|
favorite
| on:
Reminder: secret_token.rb is named so for a reason
No, you have mosunderstood me. I'm NOT storing a hash in the cookie. Instead im storing a random string. Because this string is random, there is no way that a malicious user can guess what the session code will be for a particular user id.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: