Skip to content

FOUR-16704: Session Token Not Invalidated on Logout#7396

Merged
ryancooley merged 1 commit intonextfrom
bugfix/FOUR-16704
Oct 2, 2024
Merged

FOUR-16704: Session Token Not Invalidated on Logout#7396
ryancooley merged 1 commit intonextfrom
bugfix/FOUR-16704

Conversation

@danloa
Copy link
Copy Markdown
Contributor

@danloa danloa commented Sep 20, 2024

Issue & Reproduction Steps

The problem is described in the next video:

oauth_session_left_opened-2024-09-19_09.44.51.mp4

https://drive.google.com/file/d/1ZrFNuWyK-gioGwM9XXtV9dixT398KWks/view

Solution

  • As part of the logout, the Laravel cookie is removed, so it can't be used again.

Related Tickets & Packages

Code Review Checklist

  • I have pulled this code locally and tested it on my instance, along with any associated packages.
  • This code adheres to ProcessMaker Coding Guidelines.
  • This code includes a unit test or an E2E test that tests its functionality, or is covered by an existing test.
  • This solution fixes the bug reported in the original ticket.
  • This solution does not alter the expected output of a component in a way that would break existing Processes.
  • This solution does not implement any breaking changes that would invalidate documentation or cause existing Processes to fail.
  • This solution has been tested with enterprise packages that rely on its functionality and does not introduce bugs in those packages.
  • This code does not duplicate functionality that already exists in the framework or in ProcessMaker.
  • This ticket conforms to the PRD associated with this part of ProcessMaker.

ci:next

@danloa danloa changed the title Delete Larevl cooki on logout FOUR-16704: Session Token Not Invalidated on Logout Sep 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants