Forum  Commercial Foru...  Commercial Foru...  !!! huge problem, users get sessions of other users !!! (IIS7 bug?)
Previous Previous
 
Next Next
New Post 9/23/2009 6:17 AM
Informative
  Visualizer
665 posts
1st Level Poster




!!! huge problem, users get sessions of other users !!! (IIS7 bug?) 
Modified By Visualizer  on 9/28/2009 3:08:44 AM)

We suddenly have a big problem in our production environment.

We had a user that was logged in into the application under his own name.

After lunch (half hour of inactivity) the user refreshes his screen (ie7 - F5 button) and suddenly it looks like he is logged in as another user, we can see because the username is onto the screen.

Every time the user presses F5 now he see the screen of the other user, even dialog boxes popping up and so on.

You can imagine this is an awsome big risk even if the data is from another organisation.

We use 6.3.9 / 3.5.

Any ideas how this can happend or to put us on the right track to find the problem are welcome.

 

Regards,

Tom

 

 
New Post 9/23/2009 8:25 AM
  ori.cohen
4383 posts
1st Level Poster




Re: !!! huge problem, users get sessions of other users !!! 
Modified By ori.cohen  on 9/23/2009 10:26:56 AM)

Hello Tom,

Thank you for this report.

VWG has actually not reinvented sessions or created any new infrastructure in that aspect.
We are completely based on the ASP.NET framework and the way that IIS operates.

There are only two ways that could make this happen in a VWG application, and both are highly unrecommended implementations except for very specific cases that I guess you didn't encounter here:
1. Use of static variables to keep state of the user.
2. Use of the Singleton design pattern to override use of separate sessions for different users.

Anyway, this certaily looks like something we need to research and look into, so please send us your application to Support [at] VisualWebGui [dot] com, with a link to this forum thread.
We will go through this application and look what can be causing this less then desirable behavior, and write back to you in this thread.

Regards,

Ori Cohen
Support Manager, the Visual WebGui team
 

 
New Post 9/23/2009 9:07 AM
  Visualizer
665 posts
1st Level Poster




Re: !!! huge problem, users get sessions of other users !!! 

Hi Ori, tnx for the quick response.

I guess sending the application isnt possible, it's quite a big application and it's depending on a infrastructure with SQL databases for datastorage and licensing.

The two example you gave, we didnt use them.

The problem is that i still wasn't able to reproduce it, but i saw it happening at a workstation here and it really scares me coz diffrent organisations can see there data if this happends.

Is there a possibility you give us some hints where to look at or how we can investigate it further?

Thanks in advance!

 

 
New Post 9/23/2009 9:10 AM
  happyfirst
242 posts
4th Level Poster




Re: !!! huge problem, users get sessions of other users !!! 

Also make sure you are not using ThreadStatic variables as threads get reused in an asp.net app.

 
New Post 9/23/2009 9:19 AM
  Visualizer
665 posts
1st Level Poster




Re: !!! huge problem, users get sessions of other users !!! 

Tnx happyfirst, but we did'n't use them.

 
Previous Previous
 
Next Next
  Forum  Commercial Foru...  Commercial Foru...  !!! huge problem, users get sessions of other users !!! (IIS7 bug?)
CompanionKit Bottom
.NET Web, Cloud and Mobile application delivery platform | Sitemap | Terms of Use | Privacy Statement | Copyright © 2005-2011 Visual WebGui®       Visual WebGui weblog on ASP.NET Visual WebGui Group on LinkedIn Visual WebGui updates on Twitter Visual WebGui Page on Facebook Visual WebGui YouTube Channel Visual WebGui Platform News RSS