Tag
Notes tagged “sessions”
Every note filed under sessions, newest first.
A filtered view of the notes.
2026
- One Defect, Three Surfaces
CORS allowlists, OAuth redirect URIs and open redirects have separate vulnerability literatures and the same bug — a structured identifier tested with a string operation. The fix is one sentence, and a standards body finally wrote it down.
- The Credential That Predates the Origin
Cookies do not obey the same-origin policy — they never have. Thirty years of attributes, flags and name prefixes are one long retrofit, and knowing which parts actually hold is most of session security.