[dokuwiki] Re: Bug? LDAP auth and cookie behaviour

  • From: Andrwe Lord Weber <lord-weber-andrwe@xxxxxxxxxxxxxxxxxx>
  • To: <dokuwiki@xxxxxxxxxxxxx>
  • Date: Tue, 19 Jul 2011 09:03:08 +0200

Hi Wayne,

could you please send the bug report.
I'll use it for my reporting as the problem is the same.


Kind regards,
Andrwe

On Mon, 18 Jul 2011 20:28:33 +0100 (BST), WAYNE JENNER wrote:
Andrwe,

We are experiencing similar problems, I have posted a bug report on
this and provided some background details in the bug tracker. We are
on Anteater at present, using IE7.

Initially I thought it was a server/apache issue, or a caching
problem. We extended the authentication periods both in DokuWiki and
Apache, but didn't solve this issue.

However in our case it only occurs when people are accessing DokuWiki
from within the internal network structure, if they access the Wiki
'externally' on a machine not on the internal network the problem does
not occur. This lead us to believe the problem might be with network
caching behaviour.

I must admit we hadn't consider cookie behaviour.

Whatever, we have not yet solve our problem, users get swapped e.g a
user logged in under their own log-in, sometimes find themselves,
changed to another log-in, including the privileges associated with
that log-in.

We are trying to move to MySQL authentication in an attempt to
overcome this problem.

Any help or thoughts on this gratefully received.


Wayne




--- On Mon, 18/7/11, Andrwe Lord Weber
<lord-weber-andrwe@xxxxxxxxxxxxxxxxxx> wrote:

From: Andrwe Lord Weber <lord-weber-andrwe@xxxxxxxxxxxxxxxxxx>
Subject: [dokuwiki] Bug? LDAP auth and cookie behaviour
To: dokuwiki@xxxxxxxxxxxxx
Date: Monday, 18 July, 2011, 9:58

Hi,

I've just encountered a strange behaviour.
When you use LDAP authentication and login in to the wiki while
having a cookie from an other user you'll login as this user.

Example:

- Dokuwiki (Release 2011-05-25a "Rincewind") using LDAP authentication
- user1 logs in to wiki using firefox
- firefox is closed (cookies aren't deleted, default behaviour)
- user2 starts firefox and logs in to wiki using his credentials
- user2 is logged in as user1 althought used his credentials

Is this behaviour as wanted?
Shouldn't dokuwiki create a new cookie for user2?


Kind regards,
Andrwe
-- DokuWiki mailing list - more info at
http://www.dokuwiki.org/mailinglist

--
DokuWiki mailing list - more info at
http://www.dokuwiki.org/mailinglist

Other related posts: