Introduction
This article explains security considerations for session cookies, the risks they pose, what falls within the Mendix platform’s scope, and what users need to address.
Environment
Applications hosted in Mendix Cloud
Details
If a browser extension or malicious local access has the ability to extract or manipulate cookies, it indicates a compromise at the device or browser level. This type of threat lies outside the scope of what the Mendix platform can directly prevent. As such, it's essential to ensure that local environments are secure, including keeping browsers, operating systems, and security tools up to date, and avoiding untrusted browser extensions.
Internal information related
255128, 265332
Additional information
Mendix documentation:
- Authentication Token Generation
- Session Timeout and Management
- HttpOnly and Secure Cookie Attributes
- Concurrent Login Considerations for Admin Accounts
0 Comments