"Simple session middleware for Koa. Defaults to cookie-based sessions and supports external stores. [...] The session is stored in a cookie by default, but it has some disadvantages: Session is stored on client side unencrypted [...]"

😬

Follow

Anyone up for a bet on how many Koa applications are unknowingly running with this default configuration being used for authenticating users?

· · Web · 1 · 0 · 4

@joepie91 I thought we as an industry learned the lesson of insecure defaults being bad a long time ago 😭

Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.