Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Session handling: api and webdav requests with basic auth or oauth2 tokens shall not start a session #29779

Closed
DeepDiver1975 opened this issue Dec 7, 2017 · 6 comments

Comments

@DeepDiver1975
Copy link
Member

Reasoning:

What to do:

  • sessions are only started when an explicit login via the webui is initiated
  • information currently being stored in the session needs to be store in a different location
  • analyse the information which is stored in the session and review the storage location
  • ISession and IUserSession are part of the public api - we need to continue to support this
@PVince81
Copy link
Contributor

PVince81 commented Dec 7, 2017

What about web UI?

@ownclouders
Copy link
Contributor

GitMate.io thinks the contributor most likely able to help you is @PVince81.

@DeepDiver1975
Copy link
Member Author

sessions are only started when an explicit login via the webui is initiated

@PVince81
Copy link
Contributor

PVince81 commented Apr 3, 2018

moving to planned

@PVince81
Copy link
Contributor

backlog

@DeepDiver1975
Copy link
Member Author

We will not touch these parts anymore -> close

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants