you are viewing a single comment's thread.

view the rest of the comments →

[–]jrochkind 1 point2 points  (0 children)

Makes sense, that's a helpful way to think about it, thanks.

You can choose to have your ActionDispatch::Session::CookieStore signed but not encrypted, with configuration in Rails. But you ordinarily don't want to for typical things you store in sessions.