View Issue Details

IDProjectCategoryView StatusLast Update
0015527Open Gaming Network[All Projects] Generalpublic2019-05-19 00:05
ReporterwebformAssigned Tomatt 
PrioritynormalSeverityminorReproducibilityhave not tried
Status resolvedResolutionfixed 
Product Version 
Target VersionFixed in Version 
Summary0015527: Admin credentials? autologin on a specific page?
DescriptionIssue type: Technical Website Issue
Reported from: [not specified]
by Aerotan Lightpaw
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
On the https://www.d20pfsrd.com/races/3rd-party-races/silver-games/ponykind/ page, visitors seem to be automatically logged in as user llisandur. Thankfully the administrative and editor's links still require full authentication, but this is some sort of authentication error or something similar, and it is likely somewhat dangerous for the site's stability and security.
TagsNo tags attached.

Relationships

has duplicate 0015500 closedmatt Logged into an account that is not mine 

Activities

matt

2019-05-19 00:04

administrator   ~0002123

Tweaked cache code to do an extra check for logged-in user, after monitoring for a week we've had no re-occurrence of the issue so that appears to have fixed it!

Issue History

Date Modified Username Field Change
2019-05-09 19:35 webform New Issue
2019-05-11 15:50 jreyst Assigned To => matt
2019-05-11 15:50 jreyst Status new => assigned
2019-05-19 00:04 matt Status assigned => resolved
2019-05-19 00:04 matt Resolution open => fixed
2019-05-19 00:04 matt Note Added: 0002123
2019-05-19 00:05 matt Relationship added has duplicate 0015500