Hi everyone, as far as I can find, every time user logs in with IVY Portal, the session is kept (not renewed). You can check this via JSESSIONID. Thus, it leads to session fixation attack.
May Axon.ivy provide a mechanism to prevent this kind of attack? I am using Axon.ivy 6.3.0.
Thank you.

asked 03.01.2018 at 04:25

Bao Tran
This issue has been fixed in ivy 7.1 and 7.0.4.


answered 09.05.2018 at 01:34

Alex Suter ♦♦
This is a known issue. See https://jira.axonivy.com/jira/browse/XIVY-349 Unfortunately, we cannot fix this issue without breaking RIA applications. However, we plan to drop RIA support in Axon.ivy 8. After that we can fix this issue.

Regards Reto Weiss, Axon.ivy Support


answered 04.01.2018 at 04:20

Reto Weiss ♦♦
Thank you for your answer. This means that there is nothing we can do now?

(04.01.2018 at 04:37) Bao Tran

Hello @Bao Tran, Just want to update that this issue has been fixed in Ivy 7.0.4 & 7.1 as the US stated. https://developer.axonivy.com/doc/7.1.0/new-and-noteworthy

(08.05.2018 at 23:54) ToanLC

