Impact
When restoring the cookie from the session store, the expires
field is overriden if the maxAge
field was set.
This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed.
Patches
Updating to v10.9.0 will solve this.
Workarounds
None
References
Publicly reported at: #251
Impact
When restoring the cookie from the session store, the
expires
field is overriden if themaxAge
field was set.This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed.
Patches
Updating to v10.9.0 will solve this.
Workarounds
None
References
Publicly reported at: #251