Security Problem

Added by Guillaume Lastecoueres almost 10 years ago

Hello everybody i have a big problem and i hope you will be able to help me.

I run two redmine instances on the same machine. Something like this www.x.x/redmine1 and www.x.x/redmine2

When i am connected on the first instance and i go to the second instance i am connected like an another user ... Of the second instance ... someone that i don't know... This is a problem ... and i have not found any solution that works :/ .

How can i solve this problem ?

Thanks in advance

PX9e

Replies (1)

RE: Security Problem - Added by Miguel Angel Salcedo over 9 years ago

I have the same problem.

I'm running two Redmine 1.4.4 instances on the same machine, and when I login in one of the instances and then I modify the URL to enter the second instance, I am already logged in with a different user (the user with the same internal ID that I logged in the first place, which is not the same real user in the second instance.

It is something related with the session and the domain, because if I change the domain (using a virtual domain) it works ok.

It is not related with Autologin (i have check different configurations and it always fails)

Is there a way to make this work without needing to use different domain names?

thanks,

(1-1/1)