Files
odoo_source/addons/base_import
Martin Geubelle 31664422c1 [IMP] web, *: remove explicit references to session_id
Since rev. odoo/odoo@f4d541e the `session_id` cookie uses the `httponly` flag so
it cannot be accessed through client side script. But before this rev. the
`session_id` was still provided by the server to the webclient (in session_info,
mostly) and was stored and accessible. This made XSS injection more
dangerous than they should be as it was very easy to steal the `session_id`.

As the browser automatically set the `session_id` on every request to the server,
the webclient shouldn't need any explicit reference.
2019-02-13 09:38:30 +00:00
..