Something wrong with the session expiration code. It does not expire (Tried Chrome and FFX on OS-X) and can be serious security risk.

However, if I change manual session kill with session_destroy() function, it works like a charm (please see attached patch).

Can you please review?

Thanks.

CommentFileSizeAuthor
#1 tokenauth.module.patch351 bytesirakli

Comments

irakli’s picture

StatusFileSize
new351 bytes
irakli’s picture

Status: Active » Fixed

Fixed in CVS. Waiting for the security team review to make a security patch release.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.

irakli’s picture

Status: Closed (fixed) » Fixed

Unfortunately, have not heard back from the security team, so will be releasing as bug-fix, not security update. Better than nothing, I guess.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.