Replies: 1 comment 1 reply
-
Hey! The documentation do mention that session data is persisted in an encrypted cookie by default (but we may be missing mentions of that elsewhere in the doc):
Ultimately everything that is encrypted in Marten leverages Edit: added more details in 431fced. |
Beta Was this translation helpful? Give feedback.
-
The documentation mentions that the default session store is cookie-based. However, it's not mentioned what security measures are applied. I guess it's encrypted otherwise the user could tamper with it. However, this should be made clear in the documentation in order to help developers evaluate the security model of the application.
Beta Was this translation helpful? Give feedback.
All reactions