PGU
Member
Issue: If you have two tabs open (say 1 in the admincp and one on the forumhome) and log out of one (say the forum home), you are still able to perform admin functions in the other tab. once an action is done, it logs the user back in without password prompt.
This means that if you log out in one tab, someone can still sit down do any action on the forum and then continue to act as the [formerly] logged in user.
Steps to reproduce:
login to the admin cp
open a new tab in the same browser
open the forum home (you should now be logged in with the same user name you are in the admin cp)
log out of the forum home (by clicking log out)
go to admin cp tab
make any change and submit it (i changed stuff under basic board information)
go back to the forum home tab
hit refresh
you should now be logged back in
This means that if you log out in one tab, someone can still sit down do any action on the forum and then continue to act as the [formerly] logged in user.
Steps to reproduce:
login to the admin cp
open a new tab in the same browser
open the forum home (you should now be logged in with the same user name you are in the admin cp)
log out of the forum home (by clicking log out)
go to admin cp tab
make any change and submit it (i changed stuff under basic board information)
go back to the forum home tab
hit refresh
you should now be logged back in