Reputation: 295
How can we fix the session fixation issue in web application where as i am logging in to the application using openam.
please give some suggestion .
Any help would be appriciated.
Thanks in advance.
Upvotes: 1
Views: 2458
Reputation: 8624
To mitigate session fixaction after successfull login invalidate the current session and create a new session.
The flow will be
This way session fixation can be avoided.
Upvotes: 2