[GH-ISSUE #1418] Sessions are taken over by other users #402

Open
opened 2026-02-26 18:46:53 +03:00 by kerem · 1 comment
Owner

Originally created by @Rainson12 on GitHub (Oct 22, 2024).
Original GitHub issue: https://github.com/documenso/documenso/issues/1418

Issue Description

We are facing an Issue where at random timepoints users seem to be switching the session. For example "Leoni" and "Max" are logged in and a re signing documents and then suddenly "Max" becomes "Leoni" and also sees her Documents. We faced this issue multiple times now but are not able to reproduce it. It occurs at random times. Has anyone else seen this before? We are using the "latest" Docker container.

Steps to Reproduce

We are unable to reproduce it, we were able to bruteforce it when mutliple users where using the system and constantly trying to send out documents for signing and others at the same time filling out fields. At some timepoint one user would eventually takeover the session of another user in the system.

Expected Behavior

No response

Current Behavior

No response

Screenshots (optional)

No response

Operating System [e.g., Windows 10]

No response

Browser [e.g., Chrome, Firefox]

No response

Version [e.g., 2.0.1]

documenso:latest / v1.7.2-rc.0

Please check the boxes that apply to this issue report.

  • I have searched the existing issues to make sure this is not a duplicate.
  • I have provided steps to reproduce the issue.
  • I have included relevant environment information.
  • I have included any relevant screenshots.
  • I understand that this is a voluntary contribution and that there is no guarantee of resolution.
  • I want to work on creating a PR for this issue if approved
Originally created by @Rainson12 on GitHub (Oct 22, 2024). Original GitHub issue: https://github.com/documenso/documenso/issues/1418 ### Issue Description We are facing an Issue where at random timepoints users seem to be switching the session. For example "Leoni" and "Max" are logged in and a re signing documents and then suddenly "Max" becomes "Leoni" and also sees her Documents. We faced this issue multiple times now but are not able to reproduce it. It occurs at random times. Has anyone else seen this before? We are using the "latest" Docker container. ### Steps to Reproduce We are unable to reproduce it, we were able to bruteforce it when mutliple users where using the system and constantly trying to send out documents for signing and others at the same time filling out fields. At some timepoint one user would eventually takeover the session of another user in the system. ### Expected Behavior _No response_ ### Current Behavior _No response_ ### Screenshots (optional) _No response_ ### Operating System [e.g., Windows 10] _No response_ ### Browser [e.g., Chrome, Firefox] _No response_ ### Version [e.g., 2.0.1] documenso:latest / v1.7.2-rc.0 ### Please check the boxes that apply to this issue report. - [X] I have searched the existing issues to make sure this is not a duplicate. - [X] I have provided steps to reproduce the issue. - [X] I have included relevant environment information. - [X] I have included any relevant screenshots. - [X] I understand that this is a voluntary contribution and that there is no guarantee of resolution. - [ ] I want to work on creating a PR for this issue if approved
Author
Owner

@TSP-Dev commented on GitHub (Nov 5, 2024):

Would be great if you can screenshot console, cookies session, when brute force it

<!-- gh-comment-id:2457115472 --> @TSP-Dev commented on GitHub (Nov 5, 2024): Would be great if you can screenshot console, cookies session, when brute force it
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/documenso#402
No description provided.