Re: Security hole with authenticated sessions

2010-04-15 Thread Russell Keith-Magee
On Thu, Apr 15, 2010 at 10:51 PM, subs...@gmail.com wrote: > Please note I've already consulted secur...@djangoproject.com about > this and Jacob told me to post it here if I wanted to. > > One problem with authenticated sessions is that, upon de-activation of > a user's account, any sessions that

Re: Security hole with authenticated sessions

2010-04-15 Thread subs...@gmail.com
Oh, and I apologize for the racy subject line =) On Apr 15, 10:51 am, "subs...@gmail.com" wrote: > Please note I've already consulted secur...@djangoproject.com about > this and Jacob told me to post it here if I wanted to. > > One problem with authenticated sessions is that, upon de-activation o

Security hole with authenticated sessions

2010-04-15 Thread subs...@gmail.com
Please note I've already consulted secur...@djangoproject.com about this and Jacob told me to post it here if I wanted to. One problem with authenticated sessions is that, upon de-activation of a user's account, any sessions that user has remain live until they logout. I think it would be a good