[#11933] login screen on content editor/filepicker after switching users

Created By: Matt Hornsby (DIGI3) (DIGI3)
Date Submitted: Tue Dec 04 14:15:46 -0500 2018

Version: 2.2.8
CMSMS Version: 2.2.8
Resolution: Fixed
State: Closed
Detailed Description:
To recreate:
1) Log in as admin
2) Edit a content page with wysiwyg on, and place an image using the filepicker,
then submit
3) Create another backend Admin user
4) Log out, then log in as the new user
5) Edit the content page and try placing an image. If it works, submit and log
6) Log back in as the original user, and try placing an image once more - shows
the login screen in the filepicker window.

Appears to be an incomplete session clearing?
(Note to Rob: also exists in 2.2.902 test)


Date: 2019-02-01 15:27
Posted By: Robert Campbell (calguy1000)

should be fixed in 2.2.9 and 2.3
Date: 2019-03-26 13:28
Posted By: Charles Butcher (chazzo)

Please see the latest posts in They
reference a problem with TinyMCE, which *I know is not the core*. But I think
the basic issue is the same – related to the session cookie CMSSESSIDxxxx – and
for me it persists in 2.2.10. The problem with TinyMCE occurs with https. With
http it seems to be fine.

For me, the CMSSESSIDxxxx cookie is not being cleared either on logout or at the
next login. If that is the expected behaviour, then the bug lies in TinyMCE.

But if the intention is for the CMSSESSIDxxxx cookie to be cleared, then we have
a more general problem, at least with https and on some servers.

