Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Set authentication cookie for both www. and "naked" domain URLs. #293

Open
alastairs opened this issue Jul 1, 2014 · 0 comments
Open

Set authentication cookie for both www. and "naked" domain URLs. #293

alastairs opened this issue Jul 1, 2014 · 0 comments

Comments

@alastairs
Copy link
Contributor

Initially I thought this was a security hole on the Session Details page before I twigged that the URLs were different (the direct URL to a session included the www., whereas my typed URLs did not). If I go to http://dddeastanglia.com/, I am not logged in; if I go to http://www.dddeastanglia.com/Session/Details/3136, I am logged in as me and can do everything I can do when I am logged in, such as viewing the admin area, edit my profile, and navigate around the site while remaining logged in.

Perhaps the easiest fix for this is to redirect every, via IIS config or within the app, to one or other of the hostnames so it is always the same.

Does any of that make sense? 😄

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant