Crowd session token should be unique for each user, directory, machine

XMLWordPrintable

    • Type: Suggestion
    • Resolution: Fixed
    • 1.0.3
    • Component/s: None
    • None

      The validation factors currently generate tokens based on machine specific attributes, such as remote host, user-agent, etc.

      If a user on a machine had multiple identities, then the token generated would be the same (as the machine attributes are the same).

      It would be nice if this token was unique based on the current validation factors as well as the username of the principal and the directory which the principal belongs to (uniquely identifying the principal).

            Assignee:
            shihab
            Reporter:
            shihab
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: