Announcement

Collapse
No announcement yet.

Login / Cookie / Remember Me problem...can't login

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Login / Cookie / Remember Me problem...can't login

    Hello,

    We're running 3.5.1 with security patches to 3.5.5


    The problem is, when a user tries to log in an leaves "REMEMBER ME" unchecked, it will say "Thank you for logging in, JoeBob." but when it redirects them, they will not be logged in.

    Users are only able to log in when "REMEMBER ME" is checked.

    I believe this problem appears for all users.

    I have tested it on my browser clearing all cookies & cache, and I have confirmed that my browser is accepting the cookie.


    Our board is fairly modified, but I have also tried using:
    define('DISABLE_HOOKS', true);
    in the config.php and got the same results.

    I have tried the others suggestions such as changing the cookie prefix to 'vb' from 'bb' and the running tools.php to change the cookie path and cookie domain.

    I still get the same results - the user must have "Remember Me" checked in order to log in.


    On the other hand, we CAN log in to the admincp. I'm guessing that the admincp has some routine that is the equivalent of having the "Remember Me" box checked.

    Any ideas?

  • #2
    At this point the nest step is upgrading to 3.5.5.
    Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
    Change CKEditor Colors to Match Style (for 4.1.4 and above)

    Steve Machol Photography


    Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


    Comment


    • #3
      Originally posted by Steve Machol View Post
      At this point the nest step is upgrading to 3.5.5.
      Whew. That's easier said than done. For our next major upgrade, I think we'll be updating to the 3.6.x branch after another release or two.

      Do you remember any specific code changes that dealt with this issue? Before I made this post, I searched a little on the subject and I did notice that quite a few other people had the same or similar problems relating to users being logged out right after logging in.

      Comment


      • #4
        This will work with an unmodifed 3.5.1 or 3.5.5 forum. You can try reverting your templates to see if that helps.
        Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
        Change CKEditor Colors to Match Style (for 4.1.4 and above)

        Steve Machol Photography


        Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


        Comment


        • #5
          I wonder if it has anything to do with this...

          http://www.vbulletin.com/forum/showp...30&postcount=8

          But it appears that we used the plugins for those:

          Security Fix for Issue in vBulletin 3.5.3 1.0
          This fixes a security issue in vBulletin 3.5.3 and below.

          Security Fix for Issue in vBulletin 3.5.4 1.0
          This fixes a security issue in vBulletin 3.5.4 and below.



          But I noticed there were some changes to login.php in 3.5.2 and 3.5.3 so I guess I'll diff the files and see what changed.

          Comment


          • #6
            It appears that this bug was mentioned here:

            http://www.vbulletin.com/forum/bugs3...iew&bugid=1700

            and looked at extensively and partially fixed by Scott MacVicar in this bug report:

            http://www.vbulletin.com/forum/bugs3...iew&bugid=1258


            But it also appears that some people still had the login problems after class_core.php was patched.

            I have confirmed that I have the newer " if (!defined('SKIP_SESSIONCREATE')) " routine in my class_core.php and still am having the login issue.



            But I do understand that there have been 4 releases since the 3.5.1 that we have installed.... and it is likely that this problem may have been fixed since then in one of those releases.

            I'm just wondering what the fix was so I can apply it manually, because I am unable to go up to 3.5.5 at the moment.



            Scott seems to be the person who worked a lot on this issue.


            Maybe Scott will see this and reply?

            Comment

            widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
            Working...
            X