This issue has been created
 
 
XWiki Platform / cid:jira-generated-image-avatar-03f92930-342d-496a-a7d6-842f0c61be55 XWIKI-22283 Open

Logging out does not kick the user out of realtime editing sessions.

 
View issue   ยท   Add comment
 

Issue created

 
cid:jira-generated-image-avatar-3dcfd444-c264-43a3-ac11-183e9ec6c885 Dorian Ouakli created this issue on 20/Jun/24 12:09
 
Summary: Logging out does not kick the user out of realtime editing sessions.
Issue Type: cid:jira-generated-image-avatar-03f92930-342d-496a-a7d6-842f0c61be55 Bug
Affects Versions: 15.10.10, 16.4.0, 16.5.0-rc-1
Assignee: Unassigned
Components: Realtime, Security
Created: 20/Jun/24 12:09
Priority: cid:jira-generated-image-static-major-eea006b7-25bf-4ec1-a2c5-34ea9a03e334 Major
Reporter: Dorian Ouakli
Description:

Steps to reproduce, having realtime editing enabled:

  • Ina first browser window, log-in as alice, and edit a page.
  • In an incognito window, log-in as bob, and edit the same page as alice.
  • Back to the first browser window, open a new tab and log-out from that new tab.

Expected result: Alice is kicked out of the Realtime editing session.

Actual result: Alice is still in the realtime session and can see new changes made to the document by Bob, after logging out.