Fun times with Poisoned Cookies!

Re: Fun times with Poisoned Cookies!

by Randy Thornton -
Number of replies: 0
Picture of Documentation writers


When you logout, Moodle changes the session id you had to a new one, so the old valid one does not persist (for obvious security reasons) in the cookie.

When you log back in again, it throws that placeholder id away and gives you a new one for your session (valid until you logout or the session expires according to what time you have set in the Site policies.)

Those characters strings look like valid Moodle session ids.

If the changes are happening at login and logout, that would be normal; this could be a false positive warning.