manooohar
Hi everyone,
I created a new live view app and using phx.gen.auth for authentication. How can I achieve the session tokens (cookie) works for only single system/browser.
I can copy the logged in token from dev tools and use in different browser to access page, I don’t want this to happen.
Is there a simple way to do this? Thanks in advance!!!
Trending in Questions
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
Hello,
I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
Hi everyone,
I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding.
I sta...
New
Documentation
While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
So my question is quite simple and i have found no conclusive answer on forum, google or AI.
Should we use :erlang.float for Integer to ...
New
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
I’m new to elixir and just tried to install the elixirLS extension for VScode(ium) and it is throwing some errors that I would like help ...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
Hi there! We created Gust: A task orchestrator inspired by Airflow.
For those who have never heard about Aiflow, it’s a Python-based wor...
New
Hi everyone!
The first release candidate for the Expert language server project is now available!
We’ve published a press release detai...
New
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #ai
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #elixirconf-eu
- #metaprogramming
- #hex










Showing Posts 1 to 7- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
derek-zhou
Then you need to fingerprint the browser. Search for it, there are a few ways to do it.
It may has ethical or legal consequence though.
arcanemachine
Isn’t that how every single cookie works? Does your security model really need to include “someone hacked the users’s browser”?
manooohar
I will check, thanks
manooohar
my security team asked me to add this
LostKobrakai
You cannot secure your users browser. If a cookie can be copied from (browser) a to b that’s nothing you can do to prevent this. You generally don’t even know if the request comes from a browser in the first place.
What you can look into is not accepting the cookie as valid given some additional checks you do. That’s the fingerprinting mentioned earlier. Simplest would be using IP and/or user agent checks or even more involved browser/js level stuff. All of those come with tradeoffs though. E.g. personal internet access often do not come with a stable IP, user agent strings are easier copied than the cookie, js level checks might change return value, … In the end most of those values also have ways to be set from the client, so can be worked around. Therefore in the end you’re back to “you cannot prevent this, you can only make things harder”.
derek-zhou
If your security team cannot explain to you why, then it is highly likely that they are full of it.
manooohar
Thank you all for the clarification