[jira] [Closed] (OFBIZ-9302) logout security

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Closed] (OFBIZ-9302) logout security

Nicolas Malin (Jira)

     [ https://issues.apache.org/jira/browse/OFBIZ-9302?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Jacques Le Roux closed OFBIZ-9302.
----------------------------------
    Resolution: Not A Problem
      Assignee: Jacques Le Roux

This is only a cache issue so we can close as not a problem

Because navigating in you browser cache is one thing but if you try an action on one of the pages in your cache you will be asked to sign in again.

> logout security
> ---------------
>
>                 Key: OFBIZ-9302
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-9302
>             Project: OFBiz
>          Issue Type: Bug
>          Components: ALL APPLICATIONS
>    Affects Versions: Release Branch 16.11
>            Reporter: Moatasim Al Masri
>            Assignee: Jacques Le Roux
>         Attachments: logout2.wmv, logout.wmv
>
>
> am trying to check OFBIZ security authentication, and I found when we logedout the session still open in browser, that if we press back from browser we can reopen the session and continue see our application without any authentication.
> please see the video attached : logout.wmv



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)