ä»æ¥ @mad_p ããããRTæ¥ã¦ããã®ãã¤ã¼ãã«é¢ãã¦ãã¡ãã£ã¨èª¿ã¹ãã®ã§ã¾ã¨ãã¨ãã¾ãã Security Issue in Ruby on Rails Could Expose Cookies http://t.co/JlsXVEn4rZ â Ruby on Rails News (@RubyonRailsNews) September 25, 2013 åææ¡ä»¶ Railsã§ã¯ããã©ã«ãã§sessionãcookieã«ã®ã¿ä¿åãã¦ãDBãªãmemcacheãªãã®server-side storageã«ã¯ä½ãä¿åãã¾ããã ãããCookieStoreã¨ãå¼ã°ãã¦ããã¤ã§ãã ãã®å ´åã®session cookieã¯ãRailsã®session object (Hash object) ãMarshal.dumpãã¦ããã«ç½²åãä»ããtokenã§ãã rails 4ã§ã¯ç½²åä»ãã代
{{#tags}}- {{label}}
{{/tags}}