Burp Suite User Forum

Create new post

Two session handling rules with "check session is valid"

dmsilva | Last updated: Apr 25, 2022 11:06PM UTC

I am using two session handling rules. The first to keep the session authenticated and the second to update the CSRF token. It seems that when the first rules evaluates the session as valid, the subsequent rule will not check for validity, as if the concept of a valid session is shared between the two rules. Is this normal behaviour?

Liam, PortSwigger Agent | Last updated: Apr 26, 2022 09:24AM UTC

We don't think this is normal behavior. Would it be possible to send us screenshots demonstrating your session handling configuration? If so, you can email us via support@portswigger.net. Thanks!

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.