Ossn absolutely needs cookies to protect security

Mark Culaj Posted in Performance and Scalability 7 years ago

Install Ossn
Open Firefox browser
Login as Adminstrator
Open Crome browser
Navigate to Yoursite/home
You are on admin wall

Replies
al Mark Culaj Replied 7 years ago

Exactly Arsalan, Not only but also from different device in this case mobil phone. I have deleted installation but I will reinstall it soon and also System Info.

Indonesian Arsalan Shah Replied 7 years ago

I can not reproduce issue of what you saying, cookies are not to store sessions, you are saying.

  1. You login into your website using browser A.
  2. When you open your website using browser B , it automatically login you.

Can you install System Info component and provide us your website link ? https://www.opensource-socialnetwork.org/component/view/1963/system-info

al Mark Culaj Replied 7 years ago

The problem is that storing login information only on PHP session is not sufficient to protect unauthorized access. I have entered from two different browsers (not logged in) on the same computer and also from two different devices (not logged in) on the same page. You see the page that normally they should redirect you to the login page. I think this only cookies can solve.

Indonesian Arsalan Shah Replied 7 years ago

We are not sure how do you mean by ossn needs cookies? we didn't have any cookies in ossn.