Logged in to forum in private window

About this bulletin board and the Pale Moon website

Moderators: FranklinDM, Lootyhoof

User avatar
adesh
Board Warrior
Board Warrior
Posts: 1277
Joined: 2017-06-06, 07:38

Logged in to forum in private window

Unread post by adesh » 2017-09-26, 06:57

Whenever I open a forum link ("view first unread post") in new private window, I automatically get logged in, which obviously I do not want. I cannot say with surity if it happened before, but I noticed this behaviour only yesterday (thought it to my mistake somehow) and then again today (hence the post). Has something reagrding this been changed on the forum recently?
It is happening probably because of "sid" parameter in the URL:
"viewtopic.php?f=3&t=16756&view=unread&[b]sid[/b]={{some_random_string}}#unread"

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35571
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Logged in to forum in private window

Unread post by Moonchild » 2017-09-26, 08:54

Nothing has changed in that respect. If you do not want your session to be adopted in a new private window, then make sure you end your session before opening a new private window, or strip the session ID from the URL. URL session IDs are used when cookies can't be used.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
adesh
Board Warrior
Board Warrior
Posts: 1277
Joined: 2017-06-06, 07:38

Re: Logged in to forum in private window

Unread post by adesh » 2017-09-26, 10:51

To me it seems that links contain session id when the session is restarted on the server as I have set forum to remember me. E.g. opening forum in the morning after a good night's sleep.

I have found a workaround - if the page is refreshed, new forum links are generated without session identifier. I'll just use this.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35571
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Logged in to forum in private window

Unread post by Moonchild » 2017-09-26, 11:19

Yeah, that would be correct. Sessions expire (a safety measure to prevent hijacking) and then the forum software recovers it by having the session ID passed along in the URL.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Locked