[rt-users] RT_SID cookie not invalidated at logout

Jenny Martin jenny at ebi.ac.uk
Tue Feb 19 19:32:53 EST 2013


I use RT on several computers, and found that changes I made to RT-at-a-glance
on one were not seen when I re-logged in on another.  The browser is presenting
the RT_SID cookie from a previous session, and RT then seems to use the cached
RT-at-a-glance data perhaps from /opt/rt4/var/session_data.

Also if I logout of RT and log in again as a different user, the new user is
authenticated correctly and gains the correct rights, but gets the (broken)
RT-at-a-glance settings of the previous user.

I am running RT 4.0.10 with mod_fcgid 2.3.6 and RT-Authen-ExternalAuth ldap
authentication.



More information about the rt-users mailing list