Last modified: 2014-02-20 00:32:31 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T58212, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 56212 - add ability to terminate certain login sessions
add ability to terminate certain login sessions
Status: UNCONFIRMED
Product: MediaWiki
Classification: Unclassified
User login and signup (Other open bugs)
1.22.0
All All
: Lowest enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-10-27 11:51 UTC by Dan Jacobson
Modified: 2014-02-20 00:32 UTC (History)
5 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Dan Jacobson 2013-10-27 11:51:42 UTC
In facebook ( https://www.facebook.com/settings?tab=security ),
one can selectively log ones self out of other current sessions,
but in Mediawiki, one is helpless if one wants to log out of a session for which one no longer has access to the terminal of.

Please implement being able to log out of selected other sessions, or at least a way of logging out of everything everywhere, short of changing ones password.
Comment 1 Emufarmers 2013-10-27 14:45:41 UTC
Logging out already logs you out of all your sessions.
Comment 2 Dan Jacobson 2013-10-27 14:55:12 UTC
I mean lets say I have nine sessions, eight on various computers around my house and at the lab, and one back at Bob's friend's house. I want to just terminate the latter, because there are lots of weird people at his house and I'm not going back there this week. Why should I have to hurt all my other sessions just to zap that one like I can already do in Facebook?
Comment 3 MZMcBride 2013-10-27 15:53:34 UTC
I believe this is the purpose of [[mw:Extension:SecureSessions]].
Comment 4 Tyler Romeo 2013-10-27 17:30:18 UTC
[[mw:Extension:SecureSessions]] only allows you to log out all sessions at once, not individual sessions.
Comment 5 MZMcBride 2013-10-27 17:31:34 UTC
(In reply to comment #4)
> [[mw:Extension:SecureSessions]] only allows you to log out all sessions at
> once, not individual sessions.

Hmmm, interesting. So could this be a feature request for that extension, then?
Comment 6 Dan Jacobson 2013-10-27 21:42:20 UTC
What if the ability to logout itself was left to an extension?

Then only users of the 1% of the wikis where the administrator had the grace to install such extension could log out.

In this case we are forced to leave a hanging session available at Bob's house for anyone who would like to use it.

Therefore we see that such basic security should not be left for extensions, and thus belongs in the core.
Comment 7 Tyler Romeo 2013-10-29 12:51:57 UTC
What wiki users want is not a factor in determining what features are included in MediaWiki core. If only 1% of sysadmins install the extension on their wiki, it's not MediaWiki's responsibility to correct the others. In fact, it's better if sysadmins have the choice of what they want to provide to their users

In addition, there is very little reason to have a selective logout feature. Managing sessions is usually done for security purposes, i.e., if you left your account logged in somewhere and you're worried somebody might use it. In these cases it is safer to just reset all sessions.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links