标签: ruby-on-rails security redis owasp session-store
在Ruby on Rails安全文档中写道,使用CookieStore作为会话存储是开放的,可以重放攻击: http://guides.rubyonrails.org/security.html#replay-attacks-for-cookiestore-sessions