While testing the new features for J3.9, I stumbled upon a login issue. My session was expired and I rightfully got the "invalid token" message, but I also was successfully logged in. Unfortunately I can't reproduce it again. However I tried something else and manually edited the time column in the session table and set the timestamp to a past date, which should invalidate the session, but nothing happened and again instead I was successfully logged in. Tested this on the 3.9 branch.
Labels |
Added:
?
|
Status | New | ⇒ | Discussion |
Category | ⇒ | Authentication |
Labels |
Added:
J3 Issue
|
I've not encountered that since and thus will close this.
Status | Discussion | ⇒ | Closed |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2019-05-22 06:48:52 |
Closed_By | ⇒ | Hackwar |
I've had this before too (rarely), but can't reproduce at will. I know that's not that helpful, but just confirming the issue seems to exist.