-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
The app treats all sessions as valid. There is no mechanism to expire a session (that does not depend on client-side cooperation or regenerating the Rails app secret.)
If this becomes an issue for any practical purpose, then it is time to implement real authentication (Devise or OmniAuth, maybe also Pundit).
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels