Hacker News new | ask | show | jobs
by anonymousd3vil 395 days ago
Its not best practice to store session details in URL, this can be compromised easily. Maybe try this, take the same URL with session id and launch it in incognito. If it still works, that means the service.com has a lot of security gaps to fill in. Otherwise, they might be storing it in cookies if its not accessible.
1 comments

I didn’t express myself correctly. I’m rather wondering why I can’t be automatically logged in the main service.com ? Let’s say the auth is based on serious security