This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "ESAPI Session Management"
From OWASP
Line 8: | Line 8: | ||
* Separate session management API and CSRF from the Authentication and HTTP utilities | * Separate session management API and CSRF from the Authentication and HTTP utilities | ||
+ | |||
+ | * Add a flag to the changeSessionIdentifier method to not copy session content | ||
+ | |||
+ | * |
Revision as of 14:37, 11 December 2008
Feature Overview
TODO
Possible Enhancements
- Add a secure form tag that does CSRF as well as other form protections like autocomplete
- Separate session management API and CSRF from the Authentication and HTTP utilities
- Add a flag to the changeSessionIdentifier method to not copy session content