Skip to content

Session cookie removed on on every request. #222

Answered by maxcountryman
YousofMersal asked this question in Q&A
Discussion options

You must be logged in to vote

It's up to your implementation of AuthUser. But I would be careful setting it a user ID: while it is unique, it won't account for invalidating sessions when a user changes their passwords (that's okay if you don't want that but it's generally a good practice).

Replies: 1 comment 11 replies

Comment options

You must be logged in to vote
11 replies
@YousofMersal
Comment options

@maxcountryman
Comment options

@YousofMersal
Comment options

@maxcountryman
Comment options

Answer selected by YousofMersal
@YousofMersal
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants