[rt-users] RT_SID cookie not invalidated at logout
Jenny Martin
jenny at ebi.ac.uk
Tue Feb 19 19:32:53 EST 2013
I use RT on several computers, and found that changes I made to RT-at-a-glance
on one were not seen when I re-logged in on another. The browser is presenting
the RT_SID cookie from a previous session, and RT then seems to use the cached
RT-at-a-glance data perhaps from /opt/rt4/var/session_data.
Also if I logout of RT and log in again as a different user, the new user is
authenticated correctly and gains the correct rights, but gets the (broken)
RT-at-a-glance settings of the previous user.
I am running RT 4.0.10 with mod_fcgid 2.3.6 and RT-Authen-ExternalAuth ldap
authentication.
More information about the rt-users
mailing list