Skip to content

Elaborate risks with disabling strict_user_agent_check #794

Description

@emteknetnz

Currently our docs have a Relaxing checks around user agent strings section

The warning about disabling the strict_user_agent_check should be further elaborate that why significantly increases the risk of session hijacking.

e.g.

When the strict_user_agent_check is disabled, the system no longer verifies that the user's browser (identified by its User-Agent string) matches the one stored in the session.

This significantly increases the risk of session hijacking, as an attacker who steals a session ID can use it to impersonate the user from a different browser or device.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions