ESAPI Session Management

From OWASP
Revision as of 09:37, 11 December 2008 by Jeff Williams (Talk | contribs)

Jump to: navigation, search

Feature Overview

TODO

Possible Enhancements

  • Add a secure form tag that does CSRF as well as other form protections like autocomplete
  • Separate session management API and CSRF from the Authentication and HTTP utilities
  • Add a flag to the changeSessionIdentifier method to not copy session content