Commit 0b99da11 authored by Daniel Gerhardt's avatar Daniel Gerhardt

Do not trust session creation timestamp from client

Always set `creationTime` on session creation. Sessions with invalid
timestamps might otherwise be deleted by the scheduled cleanup.
parent 47ab8f9a
Pipeline #10528 canceled with stages
......@@ -278,6 +278,7 @@ public class SessionService implements ISessionService, ApplicationEventPublishe
throw new ForbiddenException();
}
}
session.setCreationTime(System.currentTimeMillis());
handleLogo(session);
// set some default values
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment