Might be that your browser cached the admin central page. But even if so, you won't be able to execute any action (as you are not logged in).

The security filter is applied on each and every request.

Philipp Bracher


On Oct 27, 2008, at 10:47 PM, Hans Wolters wrote:

Hi all,

There is a problem when a person logs out. Hitting the backbutton allows one to hit the menu again.

In normal cases this will be due to a session validation that is only checked once people login. The advise would be to recheck if a user has a valid session on every page.

POC:

Login to the demo, call the adminCentral.html with params like ? mgnlLogout=<some kind of code> It will bring you to the login screen, press the back button and the menu still works (although the content part shows the login form.

Best regards,

Hans

----------------------------------------------------------------
for list details see
http://www.magnolia-cms.com/home/community/mailing-lists.html
----------------------------------------------------------------


----------------------------------------------------------------
for list details see
http://www.magnolia-cms.com/home/community/mailing-lists.html
----------------------------------------------------------------

Reply via email to