[TYPO3-dev] Resolved Bug 10266 (Session handling - cannot login to >1 TYPO3 installation under one domain ) now appears with 4.0.13

Ingmar Schlecht ingmar at typo3.org
Thu Jul 16 09:48:49 CEST 2009


Hi Thomas,

yes, that's true, and it has been like that since the session fixation
fix was added in some earlier version.

If you think session fixation (see wikipedia for details) is not a
problem for you, you could revert the patch in your local installation
by hand:
http://forge.typo3.org/repositories/diff/typo3v4-core?rev=4787

But other than that, we currently don't have any proper solution to that.

cheers
Ingmar


Thomas Schröder schrieb:
> Hey there,
> 
> bug 10266 [1] now appears with TYPO3 4.0.13. Tested with Firefox 3.0.11,
> Chrome 2 and IE8:
> "It is no longer possible to login (at the same time) to two or more
> TYPO3 installations located in different subfolders of the same
> (sub)domain.
> In other words, access to one installation breaks the session of the
> other(s)."
> Can somebody confirm this bug?
> 
> Best regards,
>     Thomas
> 
> [1] http://bugs.typo3.org/view.php?id=10266




More information about the TYPO3-dev mailing list