strangeness with sessions, logins, and shared browsers
Although not immediately a security issue, certainly extremely bizarro... and could cause all sorts of confusion on public terminals or shared browser sessions.
For reference I'm using Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.16) Gecko/20080702 Firefox/2.0.0.16
I created a second plurk account because I wanted to be able to preview my CSS changes from the perspective of an authenticated user other than myself.
To replicate (maybe):
1) I clicked log out.
2) Went to the sign up form.
3) Used another email and info etc.
When It showed me my timeline for the first time it had my plurks from my previous account in it, as if I was a fan of myself.
To make matters stranger yet. I switched browsers and checked my original account. Indeed. My 2nd account had added my first as a fan. I had the alert. WTF?!?
Before noticing the "fan" aspect I suspected stored passwords, cookies, cache etc and took steps to check each of those. But now that I see I fan'd myself without specifying I wanted to, I'm confident there is a bug (or 12) in here.
Hope this helps...
For reference I'm using Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.16) Gecko/20080702 Firefox/2.0.0.16
I created a second plurk account because I wanted to be able to preview my CSS changes from the perspective of an authenticated user other than myself.
To replicate (maybe):
1) I clicked log out.
2) Went to the sign up form.
3) Used another email and info etc.
When It showed me my timeline for the first time it had my plurks from my previous account in it, as if I was a fan of myself.
To make matters stranger yet. I switched browsers and checked my original account. Indeed. My 2nd account had added my first as a fan. I had the alert. WTF?!?
Before noticing the "fan" aspect I suspected stored passwords, cookies, cache etc and took steps to check each of those. But now that I see I fan'd myself without specifying I wanted to, I'm confident there is a bug (or 12) in here.
Hope this helps...
1
person has this problem
I have this problem, too!
Tell me when someone solves it.
The more people who report this problem, the more it gets noticed.
The more people who report this problem, the more it gets noticed.
Create a customer community for your own organization
Plans starting at $19/month
-
Inappropriate?Hi clickykbd,
how did you create a second account? did you just register it on a signup form? because if you've used an url or invite from your original user, you'll get added original user as a fan for a newly created user automatically.
i can't replicate this on FF3. -
I just logged out and used the "Signup" link. Didn't send any invitations to myself or anything.
Also, at the time initially, I had "remember passwords" set ON, but denied FF's request to remember during the signup form and logins with the second username. Not that it seemed to matter afterwards, but I didn't go back and try again with that turned off. -
Inappropriate?We've tried to create few accounts and can't reproduce the issue.
-
I'll try again and see what happens. -
Inappropriate?Okay on 2nd attempt (3rd account) it didn't do that. Weird. I'm fairly positive I couldn't have fan'd myself the first time... as I never went to any page that would have had a fan link between login and first timeline view.
Loading Profile...



