Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Cookies issued by Teamsite
eddie1
When a user logs in to Teamsite there are 2 cookies sent to the client:
iw
webdesk
The iw cookie exposes the User ID and Role of the logged in user in clear text which is a security issue. How can this be fixed ?
Even if these cookies are deleted, you can still access teamsite and perform different operations on it. This shows that Teamsite never uses the cookies. Is that the case ?
The expiry date of the cookies is set to a value about six months from the present date on the client machine. This value is set regardless of what ever settings you have under the [authentication] section of iw.cfg file.
The current setting in my iw.cfg file is:
[authentication]
ui_login_lifetime=0h10m0s
cookie_lifetime=0
Where the login life time is 10 minutes and cookie lifetime is set to 0 so that if the user closes down the window and accesses teamsite again within the ui_login_lifetime value, teamsite doesnt allow the user to automatically login.
Any ideas ?
Thanks in Advance.
Find more posts tagged with
Comments
abackenr
the iw_user and iw_role cookies lifetimes are not configured using in the authentication section in iw.cfg. the purpose of those cookies is solely for usability purposes, to prefill the login page (username and role fields only), to the last values entered. they are not actually used for authentication. the IW_AUTH cookie, which is configured using the authentication section in iw.cfg, and is used for authentication is strongly encrypted.
so to answer your questions:
[ The iw cookie exposes the User ID and Role of the logged in user in clear text which is a security issue. How can this be fixed ? ]
this can't be turned off unfortunately. but i'm not quite sure why it is a security issue. neither is sufficient for authentication.
[ Even if these cookies are deleted, you can still access teamsite and perform different operations on it. This shows that Teamsite never uses the cookies. Is that the case ? ]
well, TeamSite does use cookies, just not those. The important cookie is the IW_AUTH cookie which is a strongly encrypted token we use for authentication. Deleting the iw_user and iw_role cookies have no impact on authentication.