Project

General

Profile

Actions

Patch #3968

closed

session cookie path does not respect RAILS_RELATIVE_URL_ROOT

Added by Jérémy Lal about 15 years ago. Updated over 14 years ago.

Status:
Closed
Priority:
High
Assignee:
Category:
Documentation
Target version:
Start date:
2009-10-04
Due date:
% Done:

100%

Estimated time:

Description

This could be problematic, if redmine is hosted at :
mydomain.com/redmine
Then javascript at mydomain.com could access the session
cookie.
Here's a simple patch to make the cookie path follow the
RAILS_RELATIVE_URL_ROOT environment variable.
I'm wondering if it's a rails bug or feature :)


Files

03_session_path.patch (708 Bytes) 03_session_path.patch Jérémy Lal, 2009-10-05 00:02
03_session_path.patch (754 Bytes) 03_session_path.patch Tom Imrei, 2009-12-06 20:01
03_session_path.patch (863 Bytes) 03_session_path.patch corrected nil or empty patch Jérémy Lal, 2010-05-16 17:30

Related issues

Related to Redmine - Defect #5387: Invalid autenticity tokenClosed2010-04-27

Actions
Related to Redmine - Defect #5051: Cookie issue when using Redmine on FirefoxClosed2010-03-11

Actions
Actions

Also available in: Atom PDF