Hacker News new | past | comments | ask | show | jobs | submit login

FWIW, the fact that the default session store is client-side only is mentioned in the overview for beginners:

http://guides.rubyonrails.org/action_controller_overview.htm...




It's also mentioned in the security guide: http://guides.rubyonrails.org/security.html#session-storage




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: