How does devise store sessions
My goal was a bit simpler, I just wanted to make sure when a user logs out, they invalidate all sessions on all browsers. Compare the two and disallow sessions which were created too long ago. If an attacker got hold of that cookie before they logged out perhaps they were on a public computer which was recording cookies?
Switch to a server-side session store. If you store sessions on the server, you are at liberty to destroy them at any point. Store a timestamp in your session so that you can timeout a session after a certain period of inactivity.
If you use Devise, you can achieve this easily with the timeoutable module. But the longer the timeout, the less useful it is for security if the attacker gets in before hitting the timeout, they can just keep refreshing to keep their session active. Find centralized, trusted content and collaborate around the technologies you use most. Connect and share knowledge within a single location that is structured and easy to search. I've created a minimal rails app, installed devise and created a User devise model.
Everything works fine, and when I log in using remember me I get a session cookie just as expected. Now what's bugging me is : How does rails handle the session informations that the browser is passing through the cookie?
I'd naively expect some information to be stored in the database, but I don't see where. There's no such thing as session table, no session column in Users , and I couldn't find anything of interest in the tmp dir. Note that restarting the server wouldn't kill my session. It is of course expected, but now I'm really wondering what kind of magic is happening here?
The default rails session storage is CookieStore. This means that all the session data is stored in a cookie rather than in the database anywhere. In Rails 3. Rails will create a new record in your sessions table with a random session ID say, dbf6ffefb5cc Your app grabs the session ID out of your cookie, and finds its record in the sessions table.
Your cookie only contains a session ID, and your Rails app looks up the data in your session store using that ID.
When it works, storing your sessions in cookies is by far the easiest way to go. You might already be using something like Memcache to cache your partials or data. Your sessions and your cached data will be fighting for space. If you want to keep your session data around until it legitimately expires, you probably want to keep it in some kind of database.
Are you using Redis as your session store? Will it try to keep all your session data in memory? For example, if you accidentally touch the session on every request, googlebot could create hundreds of thousands of useless sessions. And that would be a bad time. Storing sessions in the cache vs. I treat session data as pretty temporary, so the cache store works well for me.
So I usually try cookie first, then cache, then database. And if you want to learn more about how Ruby and Rails internals work, take a look at this article: How do gems work? Have you slogged through the same guide three times and still don't know how to build a real app?
Does Devise create session table? If it does, how to access the session variables created by Devise? Reply to author. Report message as abuse.
Show original message. Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message.