nodebb-plugin-session-sharing icon indicating copy to clipboard operation
nodebb-plugin-session-sharing copied to clipboard

Can't logout from the admin menu

Open arkabase opened this issue 11 months ago • 0 comments

NodeBB v3.7.0 Logged in with admin user. When I click on logout at the bottom of the admin menu I am redirected to the forum homepage but still logged in. The user menu logout button works fine.

In the logs with verbose active :

[session-sharing] Payload verified
[session-sharing] Processing login for uid 1, path /le-forum/
[UserReset.cleanByUid] No tokens found for uid (1).
[session-sharing] Payload verified
[session-sharing] Re-validated login for uid 1, path /le-forum/admin
...
[user.auth] Revoking session uoe71iyPtT3YSaFMl_hIpVW3L2czgX-Q for user 1
[session-sharing] Payload verified
[session-sharing] Processing login for uid 1, path /le-forum/
[UserReset.cleanByUid] No tokens found for uid (1).

You can see the first login with the shared cookie payload, revalidated for admin access, then revokation of the session on logout, but the cookie is not deleted so the plugin revalidate the login on the homepage. Does not the cookie need to be deleted on logout ?

arkabase avatar Mar 13 '24 11:03 arkabase