Actions
Feature #3727
open
Security: Session Hijacking erschweren
Start date:
13.05.2017
Due date:
% Done:
0%
Estimated time:
Discuss:
Prio Planung:
No
Vote:
Description
- Problem 1: durch '[FE][lockIP] = 0' wird der Schutz gegen Session Hijacking fuer FE-User verringert.
- Problem 2: in QFQ ist kein 'Session Hijacking' based on changed IP detection implementiert.
- Zu 1)
- Entweder eine Extension schreiben die gewisse IPs immer zulaesst (z.B. die lokalen IPs) - es gab entsrpechende Extensions.
- Oder in QFQ diesen Check implementieren (z.B. in dem sich QFQ beendet, sollte der aktuelle FE User einer FE Gruppe angehoeren)
- Zu 2) implementieren. Am besten aehnlich konfiguriert wird '[FE][lockIP]'
Updated by Carsten Rose over 5 years ago
- Target version changed from next9 to 18.10.3
Updated by Carsten Rose over 5 years ago
- Assignee changed from Carsten Rose to Elias Villiger
Updated by Elias Villiger over 5 years ago
- Assignee changed from Elias Villiger to Carsten Rose
Updated by Carsten Rose about 5 years ago
- Target version changed from 18.10.3 to 18.12.1
Updated by Carsten Rose almost 5 years ago
- Target version changed from 18.12.1 to 141
Updated by Carsten Rose over 4 years ago
- Target version changed from 141 to QFQCD19 - waere gut
Updated by Carsten Rose almost 4 years ago
- Status changed from New to Some day maybe
Updated by Carsten Rose almost 4 years ago
- Status changed from Some day maybe to New
Updated by Carsten Rose almost 4 years ago
- Target version changed from QFQCD19 - waere gut to next6
Updated by Carsten Rose over 2 years ago
- Target version changed from next6 to next4
Updated by Carsten Rose about 1 year ago
- Target version changed from next4 to Check if 'high' is still necessary
Actions