mirror of
				https://github.com/django/django.git
				synced 2025-10-30 17:16:10 +00:00 
			
		
		
		
	Fixed a sentence in the session security docs; thanks claudep.
This commit is contained in:
		| @@ -655,8 +655,8 @@ Session security | |||||||
| ================ | ================ | ||||||
|  |  | ||||||
| Subdomains within a site are able to set cookies on the client for the whole | Subdomains within a site are able to set cookies on the client for the whole | ||||||
| domain. This makes session fixation possible if all subdomains are not | domain. This makes session fixation possible if cookies are permitted from | ||||||
| controlled by trusted users (or, are at least unable to set cookies). | subdomains not controlled by trusted users. | ||||||
|  |  | ||||||
| For example, an attacker could log into ``good.example.com`` and get a valid | For example, an attacker could log into ``good.example.com`` and get a valid | ||||||
| session for their account. If the attacker has control over ``bad.example.com``, | session for their account. If the attacker has control over ``bad.example.com``, | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user