![active_sessions_list.png](https://lab.nexedi.cn/lpgeneau/gitlab-ce/-/raw/59db98a0cabea4421434655d7f7873110363d21a/doc/user/profile/img/active_sessions_list.png)
-
Imre Farkas authored
Session ID is used as a parameter for the revoke session endpoint but it should never be included in the HTML as an attacker could obtain it via XSS.
038d5305
![active_sessions_list.png](https://lab.nexedi.cn/lpgeneau/gitlab-ce/-/raw/59db98a0cabea4421434655d7f7873110363d21a/doc/user/profile/img/active_sessions_list.png)
Session ID is used as a parameter for the revoke session endpoint but it should never be included in the HTML as an attacker could obtain it via XSS.