Skip to content
Snippets Groups Projects
  1. Aug 01, 2018
  2. Jul 31, 2018
  3. Jul 30, 2018
  4. Jul 28, 2018
  5. Jul 27, 2018
  6. Jul 26, 2018
  7. Jul 24, 2018
  8. Jul 23, 2018
  9. Jul 22, 2018
  10. Jul 20, 2018
  11. Jul 18, 2018
    • Stan Hu's avatar
      Limit the TTL for anonymous sessions to 1 hour · c559c43d
      Stan Hu authored
      By default, all sessions are given the same expiration time configured in the
      session store (e.g. 1 week). However, unauthenticated users can generate a lot
      of sessions, primarily for CSRF verification. It makes sense to reduce the TTL
      for unauthenticated to something much lower than the default (e.g. 1 hour) to
      limit Redis memory. In addition, Rails creates a new session after login,
      so the short TTL doesn't even need to be extended.
      
      Closes #48101
      c559c43d
  12. Jul 17, 2018
  13. Jul 13, 2018
  14. Jul 12, 2018
  15. Jul 11, 2018
Loading