• Do not register here on develop.twiki.org, login with your twiki.org account.
• Use View topic Item7848 for generic doc work for TWiki-6.1.1. Use View topic Item7851 for doc work on extensions that are not part of a release. More... Close
• Anything you create or change in standard webs (Main, TWiki, Sandbox etc) will be automatically reverted on every SVN update.
Does this site look broken?. Use the LitterTray web for test cases.

Item7922: Invalidate Session on Password Change

Item Form Data

AppliesTo: Component: Priority: CurrentState: WaitingFor: TargetRelease ReleasedIn
Engine   Normal Confirmed   patch 6.1.1

Edit Form Data

Summary:
Reported By:
Codebase:
Applies To:
Component:
Priority:
Current State:
Waiting For:
Target Release:
Released In:
 

Detail

Originally reported by Alexander Hook:
Failure to Invalidate Session on Password Change.

I observe that when we change password from one browser in place of session Expire from other browser its just update password from other browser and the old session got updated without being logout Steps to check session management issue on password change.

  1. Login account from two browsers at a time [ From Chrome browser and From Mozilla Firefox].
  2. Change password in setting from Chrome Browser.
  3. Now check Mozilla FireFox. (First Refresh then Auto Updated in Place of Expiration ).
  4. Your Session did not Get Updated in Place of Expiration.

Recommendations:

If Session is updating from one Browser so others should expire first to renew Session after login.

Workaround until fixed: Make sure to logout in all browsers when changing the password.

This will be released in the upcoming patch release.

-- TWiki:Main/PeterThoeny - 2020-11-16

ItemTemplate
Summary Invalidate Session on Password Change
ReportedBy TWiki:Main.PeterThoeny
Codebase ~twiki4, 6.1.0
SVN Range TWiki-6.1.0-trunk, Thu, 05 Nov 2020, build 30858
AppliesTo Engine
Component

Priority Normal
CurrentState Confirmed
WaitingFor

Checkins

TargetRelease patch
ReleasedIn 6.1.1
Topic revision: r1 - 2020-11-16 - PeterThoeny
 
This site is powered by the TWiki collaboration platform Powered by PerlCopyright © 2008-2023 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback