User is never logged out if don't close UI in browser

Bug #1348190 reported by Andrey Sledzinskiy
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Fuel for OpenStack
Opinion
Wishlist
Fuel UI Team

Bug Description

{
    "build_id": "2014-07-23_02-01-14",
    "ostf_sha": "c1b60d4bcee7cd26823079a86e99f3f65414498e",
    "build_number": "347",
    "auth_required": false,
    "api": "1.0",
    "nailgun_sha": "f5775d6b7f5a3853b28096e8c502ace566e7041f",
    "production": "docker",
    "fuelmain_sha": "74b9200955201fe763526ceb51607592274929cd",
    "astute_sha": "fd9b8e3b6f59b2727b1b037054f10e0dd7bd37f1",
    "feature_groups": [
        "mirantis"
    ],
    "release": "5.1",
    "fuellib_sha": "fb0e84c954a33c912584bf35054b60914d2a2360"
}

1. Install fuel
2. Open fuel UI and log in with default credentials admin/admin
3. Leave environment for couple of hours
4. After 2-3 hours refresh page

Expected - user is prompted to log in again
Actual - user is still logged in

It turned out that UI refresh token in every 10 minutes after logging in so you'll never be logged out, only when you close the tab
I think that it's insecure - user can leave computer for some period of time and then someone else can use it because there is no expiration

Dima Shulyak (dshulyak)
Changed in fuel:
assignee: Fuel Python Team (fuel-python) → Fuel UI Team (fuel-ui)
Changed in fuel:
status: New → Confirmed
Revision history for this message
Vitaly Kramskikh (vkramskikh) wrote :

> Expected - user is prompted to log in again
I expect the UI not to logout until I explicitly do that

Changed in fuel:
importance: Medium → Wishlist
Changed in fuel:
status: Confirmed → Opinion
milestone: 5.1 → 6.0
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.