Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hotfix v5.18.3 #2512

Merged
merged 4 commits into from Jan 25, 2023
Merged

Hotfix v5.18.3 #2512

merged 4 commits into from Jan 25, 2023

Conversation

PromoFaux
Copy link
Member

No description provided.

PromoFaux and others added 3 commits January 22, 2023 17:15
Signed-off-by: 4n4nk3 <47717886+4n4nk3@users.noreply.github.com>
Fix Improper Session Handling vulnerability of "Remember me for 7 days" functionality
@PromoFaux PromoFaux requested a review from a team January 25, 2023 18:54
@PromoFaux
Copy link
Member Author

Ah of course, the linter would not have run on the advisory PR...

@DL6ER
Copy link
Member

DL6ER commented Jan 25, 2023

Just FYI: The Pi-hole v6.0 draft has something achieving the same (but differently) since almost two year. Here, we generate a random token for every successful login and assign a dedicated timeout to it (can be very long -> persistent login). In comparison to this realization, the v6.0 approach also takes the client IP address into account so "stealing" authentication from one device to another isn't possible.

@PromoFaux PromoFaux merged commit fb1b5c3 into master Jan 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants