We have observed that after changing our password, the session identifier stays the same. In doing so, when an adversary has access to the current session identifier, he will manage to maintain an active session. How can I enforce this?
↧