Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Delete your session cookie. Or he could add a logout button.


Deleting a session cookie is not the same as a logout button, because the session needs to be terminated server-sided as well, otherwise it is still active and anyone with access to the session ID could restore the session (until the natural session timeout occurs - which entirely depends on the server's configuration).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: