agis opened this issue 11 years ago · 1 comments
I've noticed that when a user is authenticated, his session_id is reset.
Is this expected behavior?
Yes this is a feature of rails sessions that are intended to make it difficult to attack