On Dec 19, 2007 10:30 AM,  <[EMAIL PROTECTED]> wrote:

> We are running DSpace 1.4 and I have just noticed a serious issue with the
> authentication.  We are using the default implementation with the email
> address/password based login.  I have noticed that when I logout and then
> click to go onto any other page on our DSpace site it comes up in the top
> left corner that I am still logged in.

I suspect that this is the browser cache at work; I often have it
return authentication-required visited pages after I log out or my
session expires. I'm not sure what DSpace could do about that except
for no-cache tricks that break the Back button entirely (which would
be a bad, bad idea).

I'm willing to be wrong, though -- if you log out, go back to your My
DSpace page, and then click on something requiring authentication
(such as starting a new submission), does it let you do it? If so,
then there is definitely a problem!

Dorothea

-- 
Dorothea Salo                [EMAIL PROTECTED]
Digital Repository Librarian      AIM: mindsatuw
University of Wisconsin
Rm 218, Memorial Library
(608) 262-5493

-------------------------------------------------------------------------
SF.Net email is sponsored by:
Check out the new SourceForge.net Marketplace.
It's the best place to buy or sell services
for just about anything Open Source.
http://ad.doubleclick.net/clk;164216239;13503038;w?http://sf.net/marketplace
_______________________________________________
DSpace-tech mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/dspace-tech

Reply via email to