Skip to content

web-terminal: use php helper for session auth lookup#5244

Merged
imjuniper merged 4 commits into
hestiacp:mainfrom
divinity76:report260306
Mar 8, 2026
Merged

web-terminal: use php helper for session auth lookup#5244
imjuniper merged 4 commits into
hestiacp:mainfrom
divinity76:report260306

Conversation

@divinity76
Copy link
Copy Markdown
Member

No description provided.

@divinity76
Copy link
Copy Markdown
Member Author

https://github.com/numanturle said in Discord

Your fix looks good.

that's a good start :)

@divinity76 divinity76 requested a review from imjuniper March 8, 2026 00:23
@imjuniper
Copy link
Copy Markdown
Contributor

It looks good to me too, but if possible, I think we should probably change all the errors to "Unauthorized" unless in dev mode to make it harder to know what's wrong for a potential attacker.

@imjuniper imjuniper enabled auto-merge (squash) March 8, 2026 21:16
@imjuniper imjuniper merged commit 854d71b into hestiacp:main Mar 8, 2026
5 checks passed
@divinity76
Copy link
Copy Markdown
Member Author

@imjuniper I understand where you're coming from, but hiding the difference between your session id does not exist and your session id is valid, but the session is unauthenticated does not meaningfully increase security IMO.

jaapmarcus pushed a commit that referenced this pull request Mar 16, 2026
* web-terminal: use php helper for session auth lookup

* nit

* Harde cookie parsing

requested by https://github.com/numanturle
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants