Comment 9 for bug 1385564

Revision history for this message
Mahara Bot (dev-mahara) wrote : A change has been merged

Reviewed: https://reviews.mahara.org/3873
Committed: http://gitorious.org/mahara/mahara/commit/9bceca2b8a782aa61564b860a4db8743aa920cdd
Submitter: Robert Lyon (<email address hidden>)
Branch: master

commit 9bceca2b8a782aa61564b860a4db8743aa920cdd
Author: Aaron Wells <email address hidden>
Date: Wed Oct 29 01:41:13 2014 +1300

Clear secreturl access cookies on logout

Bug 1385564: This doesn't provide much additional security, because if
the access cookies are still in your browser session, then the secret URL
itself is probably still in your browser history. But if someone goes to
the trouble of logging out *and* clearing their browser history, this
will ensure that it actually does end the secreturl access cookie like
they'd expect.

Change-Id: Ia75f58015ab2cb54c9184cdc8b5bf32dfe543733