What is Nostr?
Filippo Valsorda :go: /
npub1whz…kn2m
2024-04-17 23:01:47
in reply to nevent1q…wycq

Filippo Valsorda :go: on Nostr: Hypothetically, if an application went out of their way to misuse FilesystemStore by ...

Hypothetically, if an application went out of their way to misuse FilesystemStore by not using its New API and stuffing attacker-controlled data in Session.ID (which is documented as not being safe), they could hit this.

That's *not* what happened to Palo Alto. They wrote their own Store that takes the session ID from a cookie in New without authentication.
Author Public Key
npub1whzyg92c6fsvpjjcnn504z0a2pfwenctp872sgmedqg2np4drj8qwakn2m