KamoCRM

The *** cookie on login.* is HttpOnly, and no log line carries half a session id

Fixkamo-login
Ya
24 Septemba 2026, 00:11 UTC
Mwandishi
Kamo
Ahadi ya
0eb2550

/api/login, /api/login/mfa and /api/session/select planted *** with httpOnly:false ("client- accessible for session checks") — but no browser code on login.* or kamo-internal reads it any more; kamo-internal carries the session per tab. A readable session cookie is one XSS away from a stolen session, so it is HttpOnly now. It also makes logout work as intended: the logout page deletes every cookie from script BEFORE calling /api/logout, so /api/logout never found *** to invalidate the session server-side; script can no longer delete it. Four log lines printed the first 32 hex characters of a session id (or of a login OTK) — they print lengths now.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila kitu kinaingia kwenye tovuti yako mwenyewe. Anza kwenye mpango wa bure na usome ukurasa huu tena katika mwezi mmoja.

Kuwa Huru MileleMtazamo wa bei