Skip to content

退出登录cookie未失效 #592

@lcfang

Description

@lcfang
  • I have searched the issues of this repository and believe that this is not a duplicate.

Ⅰ. Issue Description

前端退出登录后,原来的cookie:_hi_sess=xxx仍可用,存在安全风险

Ⅱ. Describe what happened

If there is an exception, please attach the exception trace:

Just paste your stack trace here!

Ⅲ. Describe what you expected to happen

Ⅳ. How to reproduce it (as minimally and precisely as possible)

  1. 登录前端
  2. 获取cookie:_hi_sess=xxx
  3. 退出登录,访问接口仍能获取到数据
Image

Ⅴ. Anything else we need to know?

Ⅵ. Environment:

  • Higress version: v2.1.7
  • OS :
  • Others:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions