Uploaded image for project: 'atlassian-seraph'
  1. atlassian-seraph
  2. SER-94

Autologin cookie should be encoded with real encryption

    • Icon: Improvement Improvement
    • Resolution: Fixed
    • Icon: Medium Medium
    • 0.10
    • None
    • None
    • true

      The autologin cookie currently isn't encrypted, which is rather alarming considering it contains the user name and password. Instead, it is XOR'ed with character offsets, which is insecure. The text, if we really need to put a user name and password in there, needs to be encrypted with a real encryption algorithm.

            [SER-94] Autologin cookie should be encoded with real encryption

            Jed Wesley-Smith (Inactive) made changes -
            Fix Version/s New: 0.10 [ 13214 ]
            Affects Version/s Original: 0.10 [ 13214 ]
            Jed Wesley-Smith (Inactive) made changes -
            Affects Version/s New: 0.10 [ 13214 ]
            Jed Wesley-Smith (Inactive) made changes -
            Link New: This issue causes SER-117 [ SER-117 ]
            Samuel Le Berrigaud made changes -
            Workflow Original: jira [ 105628 ] New: reviewflow [ 121205 ]
            Matt Ryall made changes -
            Link New: This issue relates to SER-29 [ SER-29 ]
            Don Brown (Inactive) made changes -
            Assignee New: Don Brown [ dbrown@atlassian.com ]
            Resolution New: Fixed [ 1 ]
            Status Original: Open [ 1 ] New: Resolved [ 5 ]
            Don Brown (Inactive) created issue -

              dbrown@atlassian.com Don Brown (Inactive)
              dbrown@atlassian.com Don Brown (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved:
                17 years, 45 weeks, 1 day ago

                  Estimated:
                  Original Estimate - 2h
                  2h
                  Remaining:
                  Remaining Estimate - 2h
                  2h
                  Logged:
                  Time Spent - Not Specified
                  Not Specified