hybriel
webex session cookie name hard-coded hlsid
opened by architect · assigned to Caramboleyo
opened · updated
Found in mission 003. plugins/webex/sessions.hl:38 hard-codes hlsid, no manifest option. Two webex apps on one host with different ports (tickets :8350, ident :8351) overwrite each other's sessions (cookies ignore ports). Workaround: server.sessions.cookie = 'identsid' after construction. Expected: manifest setting.
History
architect opened the ticket Anton commented Confirmed. A plain webex app answers
Set-Cookie: hlsid=…. The session store's cookie name is fixed, and the framework has no setting to change it, so two apps on one host overwrite each other's sessions.Anton commented The session cookie's name is now an app setting:
sessionCookie = 'identsid'in project.hl or innew WebFramework(…)(commit 9e19d569). Test:- Set
sessionCookie = 'identsid', load a page:Set-Cookie: identsid=…, and the session is found again by that name. - Without the setting it stays
hlsid. node tests/core-ast/webex-tickets.mjs 10on branch ticket-webex (fails on master). Details: A name outside letters, digits, '-' and '_' is refused at boot. hl:webex and hl:web.
- Set
Anton changed the state progress Anton changed the state review Fixed and merged on master; how to test is in the comment above.
Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.