Getting logged in on other people's accounts

Found a bug with the site? Let me know!
Post Reply
RemovedByRequest1
Posts: 2
Joined: Thu May 03, 2007 6:04 am
Location: Netherlands

Getting logged in on other people's accounts

Post by RemovedByRequest1 »

Hey I've been uploading a bit and noticed that if I don't go through the main www.warcraftrealms.com homepage, things turn a bit buggy. I go to WR through the following link because Chrome automatically fills it in :P http://www.warcraftrealms.com/census.php?serverid=219

The navigation buttons didn't work for me, so I just typed in the homepage myself. There I noticed I wasn't actually logged in on my own profile but some other random person's. I logged out, logged in on my own account and when I try to logout now I get this error page: http://www.warcraftrealms.com/404.php?E ... ogout=true


I don't have the 'remember me' checkbox checked so every time I visit / cookie expires, I guess I should be logged out. Sorry I can't really describe it better, it just showed up randomly I guess.

User avatar
bringoutyourdead
Forums Admin & general flunky
Posts: 1432
Joined: Fri Nov 07, 2008 1:11 pm
Location: Texas, USA

Post by bringoutyourdead »

There are a couple of issues here.

First since chrome is dropping you directly on to a realm page there is no navigation history for your back and forward buttons.
I would suggest making a favorite link for this sites homepage and using that instead of typing the url.
The auto-complete features of the browsers always assume your intent from last behavior, which is often wrong. I tell my browsers to disable auto-complete, it is more of a nuisance then a help for me.

Second cookies are always used during an active session and are keyed to your current IP address among other data items.
If you are picking up other peoples sessions, my question is are you on a public shared IP address? Public WiFi hot spot for example.

Third.. Yes Metalbeast has an issue with the logout link.
The logout link in the log in/out box on the right is incorrectly configured.
If you need to force a logout (public browser, hot spot etc.) then use the LOGOUT link under the left hand navigation Menu drop down... WARCRAFTREALMS .. then LOGOUT.

I will forward your message on to Metalbeast... as this might be a hosting ISP issue..

RemovedByRequest1
Posts: 2
Joined: Thu May 03, 2007 6:04 am
Location: Netherlands

Post by RemovedByRequest1 »

If you are picking up other peoples sessions, my question is are you on a public shared IP address? Public WiFi hot spot for example.
No, it is my home IP. I do live in a big apartment building but each place has its own address.

Thanks :)

User avatar
bringoutyourdead
Forums Admin & general flunky
Posts: 1432
Joined: Fri Nov 07, 2008 1:11 pm
Location: Texas, USA

Post by bringoutyourdead »

I have notified Metalbeast and he is planning to look over the system code to see if he can spot and fix the issue.

Post Reply