Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
WoltLab
WCF
Repository navigation
Code
Issues
148
(148)
Pull requests
8
(8)
Actions
Projects
Security and quality
Insights
More
items
Stateless guests with on-demand sessions
- #6721
#6721
Merged
dtdesign
merged 19 commits into
6.3
WoltLab/WCF:6.3
from
63-stateless-guest
WoltLab/WCF:63-stateless-guest
Copy head branch name to clipboard
Oct 1, 2026
Conversation
Commits
19
(19)
Checks
Files changed
Merged
Stateless guests with on-demand sessions
#6721
dtdesign
merged 19 commits into
6.3
WoltLab/WCF:6.3
from
63-stateless-guest
WoltLab/WCF:63-stateless-guest
Copy head branch name to clipboard
Commits
Commits on Oct 1, 2026
Stop writing guest sessions for first-visit tracking and trigger pending background queue checks in-request
dtdesign
committed
6341887
View commit details
Copy full SHA for 6341887
Browse repository at this point
Add opt-in on-demand guest sessions option and sessionless signed captcha question tokens
dtdesign
committed
f59dba5
View commit details
Copy full SHA for f59dba5
Browse repository at this point
Use a random guest attachment tmpHash instead of the session ID while on-demand guest sessions are enabled
dtdesign
committed
86dd3cf
View commit details
Copy full SHA for 86dd3cf
Browse repository at this point
Start guest sessions on demand, only once session state needs to be stored
dtdesign
committed
d9b5957
View commit details
Copy full SHA for d9b5957
Browse repository at this point
Defer the XSRF-TOKEN cookie until the guest session is persisted and accept same-origin requests from sessionless guests
dtdesign
committed
a7f0ad9
View commit details
Copy full SHA for a7f0ad9
Browse repository at this point
Extract the attachment tmpHash identifier into AttachmentHandler::getTmpHashIdentifier()
dtdesign
committed
84e4359
View commit details
Copy full SHA for 84e4359
Browse repository at this point
Add a helper to probe the legacy session
dtdesign
committed
a9c8a49
View commit details
Copy full SHA for a9c8a49
Browse repository at this point
Rotate the XSRF token on login and clear session cookies on logout and for dead sessions
dtdesign
committed
b4ddbd7
View commit details
Copy full SHA for b4ddbd7
Browse repository at this point
Improve the phrasing to highlight the benefits
dtdesign
committed
b5918a6
View commit details
Copy full SHA for b5918a6
Browse repository at this point
Refresh the XSRF token in reused AJAX and upload URLs when sending
dtdesign
committed
fd3b43d
View commit details
Copy full SHA for fd3b43d
Browse repository at this point
Ask a new captcha question when the token was already used and report stale questions as invalid
dtdesign
committed
d701bc7
View commit details
Copy full SHA for d701bc7
Browse repository at this point
Detect spiders for guests without a legacy session
dtdesign
committed
6f41290
View commit details
Copy full SHA for 6f41290
Browse repository at this point
Track ownership of guest contact form uploads with a secret uploader token instead of the session
dtdesign
committed
6c2ef6e
View commit details
Copy full SHA for 6c2ef6e
Browse repository at this point
Reset session variables and legacy session when deleting an on-demand session
dtdesign
committed
61f3f70
View commit details
Copy full SHA for 61f3f70
Browse repository at this point
Restrict the same-origin XSRF fallback for sessionless guests to unsafe HTTP methods
dtdesign
committed
5ebc831
View commit details
Copy full SHA for 5ebc831
Browse repository at this point
Do not start on-demand guest sessions for cronjob and background queue requests
dtdesign
committed
ebdd045
View commit details
Copy full SHA for ebdd045
Browse repository at this point
Do not store quote removal state in the session for guests
dtdesign
committed
915f142
View commit details
Copy full SHA for 915f142
Browse repository at this point
Require the tmpHash to delete temporary attachments of guests, preventing anyone from deleting them
dtdesign
committed
b39fa94
View commit details
Copy full SHA for b39fa94
Browse repository at this point
Reject uploader tokens with a trailing newline and keep released contact files without a token record claimed
dtdesign
committed
33da0b0
View commit details
Copy full SHA for 33da0b0
Browse repository at this point
You can’t perform that action at this time.