On Dec 19, 2007 10:30 AM, <[EMAIL PROTECTED]> wrote: > We are running DSpace 1.4 and I have just noticed a serious issue with the > authentication. We are using the default implementation with the email > address/password based login. I have noticed that when I logout and then > click to go onto any other page on our DSpace site it comes up in the top > left corner that I am still logged in.
I suspect that this is the browser cache at work; I often have it return authentication-required visited pages after I log out or my session expires. I'm not sure what DSpace could do about that except for no-cache tricks that break the Back button entirely (which would be a bad, bad idea). I'm willing to be wrong, though -- if you log out, go back to your My DSpace page, and then click on something requiring authentication (such as starting a new submission), does it let you do it? If so, then there is definitely a problem! Dorothea -- Dorothea Salo [EMAIL PROTECTED] Digital Repository Librarian AIM: mindsatuw University of Wisconsin Rm 218, Memorial Library (608) 262-5493 ------------------------------------------------------------------------- SF.Net email is sponsored by: Check out the new SourceForge.net Marketplace. It's the best place to buy or sell services for just about anything Open Source. http://ad.doubleclick.net/clk;164216239;13503038;w?http://sf.net/marketplace _______________________________________________ DSpace-tech mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/dspace-tech

