You are viewing a plain text version of this content. The canonical link for it is here.
Posted to user@openmeetings.apache.org by Varga Balázs <jo...@gmail.com> on 2020/04/09 07:48:49 UTC

REST user login session not change

Hello Maxim!

I try this:

Login on API as USER1, success, get hash. I check in catalina logs, 
identifyed as user_id=1, good.

Try change logged in user (repeat login with new auth data): login again 
as USER2, success, get hash. I check in catalina logs, identifyed by 
previous user  user_id=1 this is bad.

In REST not found "logout".


This test process is failed:

Login as SOAP privileged user, create new user and your own room, and 
try switch login to new user and make another process own name.


-- 
Varga Balázs
+36-70-389-4753
SZHWEB Bt.


Re: REST user login session not change

Posted by Maxim Solodovnik <so...@gmail.com>.
On Fri, 10 Apr 2020 at 03:32, Varga Balázs <jo...@gmail.com> wrote:

> "This is not clear
> you call /user/login?user=user2&pass=pass2
>
> And get Authenticated as user1 ?
>
> I just have checked this and can't confirm
> Everything works as expected"
>
> Yes, this is a problem!
>
> The second login can"t change user in backend or logging info have bug.
>
>
> I try login first user1:pass1, try many soap method  and switch login as
> user2:pass2, try sap methods is failed http405, in catalina log show
> user_id not changed.
>

please provide the requests you did
So i can see what is wrong


>
>
>
> 2020. 04. 09. 16:40 keltezéssel, Maxim Solodovnik írta:
>
>
>
> On Thu, 9 Apr 2020 at 14:49, Varga Balázs <jo...@gmail.com> wrote:
>
>> Hello Maxim!
>>
>> I try this:
>>
>> Login on API as USER1, success, get hash. I check in catalina logs,
>> identifyed as user_id=1, good.
>>
>
> This is expected :)
>
>
>>
>> Try change logged in user (repeat login with new auth data): login again
>> as USER2, success, get hash. I check in catalina logs, identifyed by
>> previous user  user_id=1 this is bad.
>>
>
> This is not clear
> you call /user/login?user=user2&pass=pass2
>
> And get Authenticated as user1 ?
>
> I just have checked this and can't confirm
> Everything works as expected
>
>
>>
>> In REST not found "logout".
>>
>>
> This is by design
>
>
>>
>> This test process is failed:
>>
>> Login as SOAP privileged user, create new user and your own room, and
>> try switch login to new user and make another process own name.
>>
>>
> This is something I don't understand
> please re-phrase
>
>
>>
>> --
>> Varga Balázs
>> +36-70-389-4753
>> SZHWEB Bt.
>>
>>
>
> --
> Best regards,
> Maxim
>
> --
> Varga Balázs
> +36-70-389-4753
> SZHWEB Bt.
>
>

-- 
Best regards,
Maxim

Re: REST user login session not change

Posted by Varga Balázs <jo...@gmail.com>.
"This is not clear
you call /user/login?user=user2&pass=pass2

And get Authenticated as user1 ?

I just have checked this and can't confirm
Everything works as expected"

Yes, this is a problem!

The second login can"t change user in backend or logging info have bug.


I try login first user1:pass1, try many soap method  and switch login as 
user2:pass2, try sap methods is failed http405, in catalina log show 
user_id not changed.



2020. 04. 09. 16:40 keltezéssel, Maxim Solodovnik írta:
>
>
> On Thu, 9 Apr 2020 at 14:49, Varga Balázs <joinfok@gmail.com 
> <ma...@gmail.com>> wrote:
>
>     Hello Maxim!
>
>     I try this:
>
>     Login on API as USER1, success, get hash. I check in catalina logs,
>     identifyed as user_id=1, good.
>
>
> This is expected :)
>
>
>     Try change logged in user (repeat login with new auth data): login
>     again
>     as USER2, success, get hash. I check in catalina logs, identifyed by
>     previous user  user_id=1 this is bad.
>
>
> This is not clear
> you call /user/login?user=user2&pass=pass2
>
> And get Authenticated as user1 ?
>
> I just have checked this and can't confirm
> Everything works as expected
>
>
>     In REST not found "logout".
>
>
> This is by design
>
>
>     This test process is failed:
>
>     Login as SOAP privileged user, create new user and your own room, and
>     try switch login to new user and make another process own name.
>
>
> This is something I don't understand
> please re-phrase
>
>
>     -- 
>     Varga Balázs
>     +36-70-389-4753
>     SZHWEB Bt.
>
>
>
> -- 
> Best regards,
> Maxim

-- 
Varga Balázs
+36-70-389-4753
SZHWEB Bt.


Re: REST user login session not change

Posted by Maxim Solodovnik <so...@gmail.com>.
On Thu, 9 Apr 2020 at 14:49, Varga Balázs <jo...@gmail.com> wrote:

> Hello Maxim!
>
> I try this:
>
> Login on API as USER1, success, get hash. I check in catalina logs,
> identifyed as user_id=1, good.
>

This is expected :)


>
> Try change logged in user (repeat login with new auth data): login again
> as USER2, success, get hash. I check in catalina logs, identifyed by
> previous user  user_id=1 this is bad.
>

This is not clear
you call /user/login?user=user2&pass=pass2

And get Authenticated as user1 ?

I just have checked this and can't confirm
Everything works as expected


>
> In REST not found "logout".
>
>
This is by design


>
> This test process is failed:
>
> Login as SOAP privileged user, create new user and your own room, and
> try switch login to new user and make another process own name.
>
>
This is something I don't understand
please re-phrase


>
> --
> Varga Balázs
> +36-70-389-4753
> SZHWEB Bt.
>
>

-- 
Best regards,
Maxim