Project

General

Profile

Actions

Bug #7400

closed

Duplicate login does not invalidate cookies

Added by krileon over 5 years ago. Updated about 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Start date:
03 January 2019
Due date:
% Done:

100%

Estimated time:

Description

The duplicate login check does check for and delete duplicate sessions, but on refresh Joomla recreates the session from the cookie. At least 1 of the users cookies (duplicate user attempting to login) should be able to be invalidated.

https://www.joomlapolis.com/forum/153-professional-member-support/240296-cb-antispam-problem#309555

Actions #1

Updated by krileon about 5 years ago

Confirmed. Remember Me bypasses normal login procedures and restores the session. Either need a means of invalidating the cookies along with deleting the session or a means of intercepting the remember me session restore.

Actions #2

Updated by krileon about 5 years ago

Remember Me key validation is stored in __user_keys. Clearing it will clear the remember me and resolve this issue.

Actions #3

Updated by krileon about 5 years ago

  • Status changed from Assigned to Resolved
  • % Done changed from 0 to 100
Actions #4

Updated by krileon about 5 years ago

  • Target version changed from 918 to 4.0.0
Actions #5

Updated by krileon about 5 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF