-
Task
-
Resolution: Fixed
-
Minor
-
2.1
-
None
-
MOODLE_21_STABLE
-
MOODLE_22_STABLE
-
w27_
MDL-28280_m22_usesid -
This was an experimental hack designed for the first generation of japanese smart phones that did not support sessions in built-in browser.
Why remove?
- it is a big security hole allowing session fixation attacks
- all recent smart phones support sessions
- buggy and unmaintained code
- it was abused to work around site misconfiguration (Moodle 2.x actively prevents this now)
- some people thought that it might help then with cookie privacy issues (wrong, session cookies are exception)
I would really like to get this removed from 2.2 asap...
- has a non-specific relationship to
-
MDL-28158 European Cookie Law
-
- Closed
-