keybase / keybase/keybase-issues
Session cookie does not expire reasonably.
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
The session cookie I have right now expires April of 2015.
For a security-centric webapp, this seems stupendously long. I'd be much more comfortable with a timeout of something like an hour assuming no activity. That's longer than a bank, shorter than Facebook.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by locating the session-cookie configuration and checking how its expiry is calculated. The issue's proposed outcome is an inactivity timeout of about one hour, but the payload names no file, test, or entry point; verify the behavior with the relevant session or authentication tests.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100