XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    xoa password change bug - to verify

    Scheduled Pinned Locked Moved Xen Orchestra
    10 Posts 4 Posters 1.9k Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • akurzawaA Offline
      akurzawa
      last edited by

      @olivierlambert i Think i've found a ugly bug in xoa - today at work I've changed passwords for xoa admin user, at home I've got laptop on which I was logged in to xoa for few days, and unfortunately on my laptop I can still do anything on any server... I'm still legged in xoa despite password have changed, so not good. Can You verify that on your site?

      I think that we need something that will check if the password was not changed and then will log off user in that case.

      1 Reply Last reply Reply Quote 0
      • olivierlambertO Offline
        olivierlambert Vates 🪐 Co-Founder CEO
        last edited by

        If you selected "Remember me" when you connected, it's not a bug, but a feature. However, you can manage the token expiration time and put a lower value.

        1 Reply Last reply Reply Quote 0
        • N Offline
          nhanlon
          last edited by

          It's just a way of doing token expiration. One solution to this is to have a button on the user's page to retract all tokens for a user after changing the password.

          akurzawaA 1 Reply Last reply Reply Quote 0
          • akurzawaA Offline
            akurzawa
            last edited by akurzawa

            For me it's a "bug"... When I suspect that someone know my password I'm chanaging the password for xoa, so no one else can access the system but me.

            1 Reply Last reply Reply Quote 0
            • olivierlambertO Offline
              olivierlambert Vates 🪐 Co-Founder CEO
              last edited by

              Ping @julien-f

              1 Reply Last reply Reply Quote 0
              • akurzawaA Offline
                akurzawa @nhanlon
                last edited by

                @nhanlon said in xoa password change bug - to verify:

                token expiration

                where to set the token time?

                1 Reply Last reply Reply Quote 0
                • julien-fJ Offline
                  julien-f Vates 🪐 Co-Founder XO Team
                  last edited by

                  @akurzawa said in xoa password change bug - to verify:

                  For me it's a "bug"... When I suspect that someone know my password I'm chanaging the password for xoa, so no one else can access the system but me.

                  I don't think removing all tokens on password change is a good idea, XO should provide an explicit way to do this, like a big button on the user settings page, what do you think?

                  @akurzawa said in xoa password change bug - to verify:

                  where to set the token time?

                  You can override these settings in your xo-server's config: https://github.com/vatesfr/xen-orchestra/blob/1cdd1fa00ea2549fdebbf72da0edc91debd98908/packages/xo-server/config.toml#L36-L46

                  1 Reply Last reply Reply Quote 0
                  • akurzawaA Offline
                    akurzawa
                    last edited by

                    @julien-f said in xoa password change bug - to verify:

                    I don't think removing all tokens on password change is a good idea, XO should provide an explicit way to do this, like a big button on the user settings page, what do you think?

                    Just like facebook or gmail - when You change your password you are asked if you want to log off from all devices/sessions - maybe like that?

                    1 Reply Last reply Reply Quote 0
                    • julien-fJ Offline
                      julien-f Vates 🪐 Co-Founder XO Team
                      last edited by

                      @akurzawa said in xoa password change bug - to verify:

                      Just like facebook or gmail - when You change your password you are asked if you want to log off from all devices/sessions - maybe like that?

                      Good idea, would you mind creating a ticket for this?
                      https://github.com/vatesfr/xen-orchestra/issues/new

                      1 Reply Last reply Reply Quote 0
                      • akurzawaA Offline
                        akurzawa
                        last edited by akurzawa

                        Will do. Done.

                        1 Reply Last reply Reply Quote 0

                        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                        With your input, this post could be even better 💗

                        Register Login
                        • First post
                          Last post