All fixes

Rotate the session ID after login

session-fixation

If the session ID survives login, an ID planted beforehand keeps working afterwards. Issue a fresh session ID every time someone authenticates.

Why this matters

Your site doesn't change the session ID after login. Exploiting this requires XSS or subdomain cookie planting to deliver the fixed session ID — not independently exploitable.

Express

  1. 1 Regenerate the session ID after successful login
javascript
app.post('/login', (req, res) => {
  // ... authenticate user
  req.session.regenerate((err) => {
    if (err) return next(err);
    req.session.userId = user.id;
    res.redirect('/dashboard');
  });
});

Does your app still have this?

Scan your domain