Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apigee Developer Portal Kickstart 9.5.11 version allows concurrent user login - Session management not working #1105

Open
mnimakwala opened this issue Dec 22, 2024 · 2 comments
Labels
bug Something isn't working

Comments

@mnimakwala
Copy link

Description

User from one machine with its credentials is able to login to another machine

Apigee Info

We are using Apigee OPDK version 4.52.00.

Steps to Reproduce

Steps to reproduce the behavior:

  1. Go to 'Drupal web site'
  2. Enter 'User id and password'
  3. Click on Login buttong
  4. User will be login to Drupal
  5. Go to another machine and login to 'Drupal website'
  6. User will be able to login to Drupal

Actual Behavior

User should be asked that you have already login to one machine. Your session is active on machine 1. Do you want to continue or disconnect previous session.

Expected Behavior

Application to ask for prompt saying 'Your session is active. Do you want to continue or discontinue session'.

Screenshots

NA

Notes

This is vulnerable as session management is not properly maintained in this version.

Version Info

Apigee Developer Portal Kickstart version - 9.5.11
Apigee version - 4.52.00

@mnimakwala mnimakwala added the bug Something isn't working label Dec 22, 2024
@kedarkhaire
Copy link
Collaborator

Hi @mnimakwala

Thanks for bringing this to our eyes, we will have a internal dicussion on it and will update here.

@kedarkhaire
Copy link
Collaborator

Hi @mnimakwala

To be very clear, this issue occurs on all Drupal versions, I checked.
I will address this issue on our next to next release, I have added in our queue, but many things are in process, so it will take some time.

In the mean time, if you are having solution for this issue, we are open for your contribution on this.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants