-
Notifications
You must be signed in to change notification settings - Fork 67
Open
Description
Hi team,
we found a problem related to session cookie generated by authservice (__Host-AIS_session).
- Login with 2 different account (UserA,UserB) from 2 different browser
- Replace the cookie value of UserB with one from UserA
- Refresh browser of UserB
- Active session is transferred from UserA to UserB
How we can avoid this? Is there a way to tie __Host-AIS_session to browser cookie?
Thanks in advance for your help
Metadata
Metadata
Assignees
Labels
No labels