paulgorman.org

< ^ txt

Mon Oct 3 10:11:22 EDT 2022 ======================================== Slept from eleven to six-thirty without waking. Sunny, with a high near 64. East northeast wind 3 to 7 mph. Feeling low energy this morning. Slight headache. # Work eMNEPA call, USDA ERMS call, work on e-signature paper # Home * [x] think about user sessions for Go Web Base * [ ] go to bed a little early Read more of The Searcher. Fifteen-minute walk at lunch. Sunny and not hot. Saw a little white butterfly. Go Web Base user sessions. What if we: 1. On service startup, set a small magic number, like the current millisecond. 2. When we add a session user session to the Sessions slice, we add the magic number to the index of the session slice, and prepend that to the cookie value. Doing this: * is more secure/obscure than including some permutation of the user ID in the cookie * saves us iterating through the sessions array every time Even if an attacker starts guessing slice index values, we still check the random cookie session token value. Servings: grains 3/6, fruit 1/4, vegetables 2/4, dairy 2/2, meat 1/3, nuts 1/0.5 Breakfast: banana, cartros, falafel wrap Lunch: burrito Dinner:

< ^ txt