clef/clef-wordpress

Security: Session Will Not Timeout When Machine is In Standby

Closed this issue · 6 comments

I was discovered today that if a workstation is put into standby (while logged into WP) or a laptop lid is closed, Clef will not end the session.

Steps to recreate:

  1. Login to WP using Clef
  2. Do work. . . . .
  3. Put workstation into standby or close lid on laptop
  4. Let Clef session time out or log out manually using the device app
  5. Log into workstation or laptop (min/hrs/day later)
  6. Continue working in the WP admin area (Your still logged in!)

Tested in Chrome (on Chromebook and Windows) and IE10+

This is a huge security issue that needs the upmost attention

Looking into this now. This is likely a site-specific issue - can you email us at support@getclef.com so we can investigate?

Hi jessepollak,

It was brought to my attention by a team member so I tested it on a site I am working on - He is working on another site on separate servers so it isn't "a site-specific issue". Thnx

Thanks for the additional information. Do these sites share any similar plugins or custom code? Can you share the URLs for their login pages?

Sorry, I am traveling but I can say nothing else is installed on the site I started working with today (still with the Twenty Fifteen

Can you verify that you are logged out when the machine isn't in standby?

Closing as this has not been seen again. Please reopen if it's still an issue.