Binding of IP address with Session id

前端 未结 4 2143
情话喂你
情话喂你 2021-02-10 02:36

To prevent the session fixation problem, how can we bind the IP address with the session id? Is it possible to bind the session id with that of the IP address??

4条回答
  •  闹比i
    闹比i (楼主)
    2021-02-10 03:34

    You can, but its not such a good idea. If your client is behind a farm of proxies their external IP address may change on every request. AOL do this, for example.

提交回复
热议问题