Currently I use Rack: Session: Pool in sinatra but I need to switch to Rack :: Session :: EncryptedCookie in order to increase concurrency.
Before modifying my code I would like to know how safe it is to save the whole session with Rack :: Session :: EncryptedCookie
I understand that the user's identification data is cryptographically signed but I see that the rack_session variable is encrypted in the browser and available to the user.
I want to know if a person with the necessary knowledge can decrypt that hash on the user's side and get to obtain its structure to enter the site as if it were another user.