Information Required No Code Attached Yet
avatar Hackwar
Hackwar
6 May 2020

Steps to reproduce the issue

Go to the user manager, edit your super user and maybe save it once to generate a token in the "Joomla API Token" tab. Now set the "Reset" switch to yes and save again. Notice that the token stays the same.

Expected result

The token changes.

Actual result

The token stays the same

Additional comments

I couldn't find any code related to the reset in the plg_user_token plugin. Is this maybe currently missing?

avatar Hackwar Hackwar - open - 6 May 2020
avatar joomla-cms-bot joomla-cms-bot - change - 6 May 2020
Labels Added: No Code Attached Yet
avatar joomla-cms-bot joomla-cms-bot - labeled - 6 May 2020
avatar brianteeman
brianteeman - comment - 6 May 2020

I can not confirm - working fine for me

mods

avatar richard67
richard67 - comment - 6 May 2020

I can't reproduce either. What I've noticed is that the first 14 characters of the token remain the same, so on a small screen it may appear as if it had not changed.

avatar Quy
Quy - comment - 6 May 2020
avatar jwaisner
jwaisner - comment - 6 May 2020

@Hackwar can you retest this? It seems it is not reproducible by many. Is there any additional environmental elements to take into account?

avatar jwaisner jwaisner - change - 6 May 2020
Status New Information Required
Build staging 4.0-dev
avatar richard67
richard67 - comment - 7 May 2020

I still think @Hackwar was just confused by the first 14 characters of the tokens always being equal, but the rest not, and on small screen you only see those 14 characters, so it appears as if the token wouldn't change.

avatar Quy
Quy - comment - 7 May 2020

I thought that too initially, so this can be closed.

avatar richard67
richard67 - comment - 7 May 2020

Let's wait a bit before we close it, maybe we get feedback before.

avatar Hackwar
Hackwar - comment - 7 May 2020

I've checked this quickly on that installation again and the tokens are both 100% identical. However I have to do some more tests and see if there are some side effects which come into play here. Anyway, I did the necessary steps probably 5 times and I always get the same token. Will report back soon.

avatar richard67
richard67 - comment - 7 May 2020

Maybe that installation is broken somehow?

Does it have the code which Quy linked above? https://github.com/joomla/joomla-cms/blob/4.0-dev/plugins/user/token/token.php#L296

avatar Quy Quy - change - 13 May 2020
Labels Added: Information Required
avatar Quy Quy - labeled - 13 May 2020

Add a Comment

Login with GitHub to post a comment