actix/actix-extras

customizable session key generator

開放

#497 建立於 2025年1月21日

 (6 則留言) (0 個反應) (0 位負責人)Rust (227 個分叉)auto 404
A-sessionC-improvementgood first issue

倉庫指標

星標
 (889 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

The OWASP guidelines (the same linked from the comment on generate_session_key) suggest that session ids should be 64 bits long, not 64 characters as implemented in generate_session_key. If you represent a 64 bit long integer as a hexidecimal number, it is only 16 characters long instead of 64.

Is there any chance that you might consider the following replacement for generate_session_key?

fn generate_session_key() -> SessionKey {
    let key: u64 = rand::rng().random();
    let key_str = format!("{:x}", key);
    key_str.try_into().unwrap()
}

This would allow session keys to be far shorter while still complying with the OWASP guidelines. These shorter ids would take less space in storage as well. This could be really beneficial to sites with large numbers of sessions.

貢獻者指南