[Tickets #9466] Re: If ip/browser changes during Horde session its not possible to login again

bugs at horde.org bugs at horde.org
Thu Dec 23 18:27:09 UTC 2010


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/9466
------------------------------------------------------------------------------
  Ticket             | 9466
  Updated By         | Michael Slusarz <slusarz at horde.org>
  Summary            | If ip/browser changes during Horde session its not
                     | possible to login again
  Queue              | Horde Framework Packages
  Version            | Git master
  Type               | Bug
  State              | Resolved
  Priority           | 1. Low
  Milestone          |
  Patch              |
  Owners             | Michael Slusarz
------------------------------------------------------------------------------


Michael Slusarz <slusarz at horde.org> (2010-12-23 13:27) wrote:

> The only problem i see is this:
> - User A is a legitimate user that is logged in.
> - User B somehow got user's A cookies
> With this patch, user B will get the message stating that it seems  
> is browser has changed, and user A will be logged out with no reason  
> (at least he will not get none)

User A will be logged out with a 'session expired' message.  I don't  
see what is wrong with this: granted that it is not as detailed as the  
session IP change message, but it is an accurate statement.






More information about the bugs mailing list