KamoCRM

The *** cookie on login.* is HttpOnly, and no log line carries half a session id

Fixkamo-login
ส่งแล้ว
24 กันยายน 2569 เวลา 00:11 UTC
ผู้เขียน
Kamo
ตั้งค่า
0eb2550

/api/login, /api/login/mfa and /api/session/select planted *** with httpOnly:false ("client- accessible for session checks") — but no browser code on login.* or kamo-internal reads it any more; kamo-internal carries the session per tab. A readable session cookie is one XSS away from a stolen session, so it is HttpOnly now. It also makes logout work as intended: the logout page deletes every cookie from script BEFORE calling /api/logout, so /api/logout never found *** to invalidate the session server-side; script can no longer delete it. Four log lines printed the first 32 hex characters of a session id (or of a login OTK) — they print lengths now.

เปลี่ยนแปลงทั้งหมด

เหมือนที่คุณเห็นการขนส่ง?

ทั้งหมดของมันมาถึง ในที่ทํางานของคุณเอง เริ่มที่แผนฟรี และอ่านหน้านี้อีกครั้งในเดือน.

เริ่ม เป็น อิสระ ตลอด ไปแสดงพริ้นซ์