[Tickets #2974] Logout incomplete, leaving non-terminated cookies behind

bugs@bugs.horde.org bugs at bugs.horde.org
Wed Nov 16 20:33:15 PST 2005


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/?id=2974
-----------------------------------------------------------------------
 Ticket             | 2974
 Updated By         | Chuck Hagenbuch <chuck at horde.org>
 Summary            | Logout incomplete, leaving non-terminated cookies behind
 Queue              | IMP
 Version            | 4.0.3
 State              | Feedback
 Priority           | 2. Medium
 Type               | Bug
 Owners             | 
-----------------------------------------------------------------------


Chuck Hagenbuch <chuck at horde.org> (2005-11-16 20:33) wrote:

There is no reason that an existing Horde cookie should cause login to fail.
For instance, if a site's session storage were to reset for some reason, I
should be able to login even though I have an existing cookie.

Besides, we set a _new_ session cookie forcibly on login to prevent session
fixation. So something odd is going on for you, either in the browser (is
this consistent on all platforms for you? Have you tested multiple
browser/os combinations?) or the PHP side.




More information about the bugs mailing list