Last modified: 2013-02-06 16:28:36 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T34144, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 32144 - When user is logging out via HTTPS, insecure HTTP cookies keeping logged in state should be cleared as well
When user is logging out via HTTPS, insecure HTTP cookies keeping logged in s...
Status: NEW
Product: Wikimedia
Classification: Unclassified
SSL related (Other open bugs)
wmf-deployment
All All
: Normal normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-11-02 14:20 UTC by Liangent
Modified: 2013-02-06 16:28 UTC (History)
5 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Liangent 2011-11-02 14:20:42 UTC
Or if the user was logged in via http and is logging out via https, the logged-in state in http will be kept.
Comment 1 Andre Klapper 2013-01-29 18:01:29 UTC
Confirming: When I log in via HTTP and log out via HTTPS, I'm still logged in via HTTP. Tested with Opera 12.02 (removed any cookies before) on cs.wikipedia.org.

Wondering if bug 20643 would bring any changes. Probably not.
Comment 2 Bawolff (Brian Wolff) 2013-02-06 16:28:36 UTC
(In reply to comment #1)
> 
> Wondering if bug 20643 would bring any changes. Probably not.

That bug is long fixed for all but a few special cases...

When you log out, wouldn't you want all your sessions to be logged out (even for other sessions for other computers)?

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links