Announcement

#1 2013-06-27 23:30:34

kyp_
Member
2013-06-17
84

[resolved] Session cookie expires instantly (Authorization Problem)

Hi :)

Update
--------------------------------------------------------

Seems to be a session expires cookie problem (I'm guessing wildly here :) )
Btw, my browser is firefox and it happens on 2 different FF profiles.

After visiting the site with a clean cache + no cookies I received as guest
visit from around 28.June 14.39h (gmt+1):
from Firefox: pwg_id: vo4u65o2lrm0du1v9o6jlf70j3

from piwi_sessions: expires 2013-06-28 05:39:53
(server local time is -9h, I guess here)

After login as admin I've had the 2nd id:
28.June 14.41h gmt+1
Firefox: pwg_id: hk5gtudruqh1npom9j4cl088p0

from piwi_sessions: expires 2013-06-28 05:41:10


Now the interesting part. I've set the expiration date to 1.July and it all works so far in the batch manager (no wrong mass tags of the whole caddie, not loosing album filter, no authorization msg)

Now at least I can continue working off the caddie, "but" I'm guessing Guest Visitors will constantly receive new cookies all the time since they all are expired in a second? Therefore photo visit and rating counts will get mixed up ?


Update 2
--------------------------------------------------------
Problem still occured after trying to remove a tag from the tag page.
In FF Browser I seemed to have set under Page Info>Permissions> cookies set to "allow for session"


Update 3
--------------------------------------------------------

not authorized- Error happened again while trying to remove a tag on the tag-page in admin home

http://www.mysite.com/admin.php?page=tags
You are not authorized to access the requested page
   Identification Home

FF Cookie Info:
1st cookie:
pwg_id
f9tro6blcoqdbnqa7cl444npm5
mysite.com
/
At end of session

2nd cookie:
pwg_remember
1-1372430380-phs0BTQYDOGUyIcfXtDwpjBa05o%3D
www.mysite.com
/
At end of session

3rd cookie:
pwg_id
id6eu1kapfaujn219feprlhso0
/
At end of session


all cookies removed, browser closed

New test:
login as admin today, 2013-06-28, 16.57h (gmt+1) at www.mysite.com (and not mysite.com{without www.})

FF Browser Cookie Info:

__cfduid
d5039aa1c5bdeb868817e11cb7451d7a11372431455
.mysite.com
/
Thuesday, 24. December 2019 00:49:57


pwg_remember
1-1372431486-0rUgWF38Dlbi564lCbQEDrKxZO0%3D
www.mysite.com
/
Thuesday, 27. August 2013 16:58:02

pwg_id
ot549eqfs37j8obfl46ancptv2
www.mysite.com
/
At end of session


I then tried to create new tag in the tag page
ERROR again, ...not authorized...


sql piwi_sessions is saying:
ADF5ot549eqfs37j8obfl46ancptv2 

( I'm guessing the first 4 digits are the permision category or something "ADF5", if I search just ADF5 I'll get 14 total rsults from piwi_images, even though I only work with 1 admin account)
Expires 2013-06-28 07:59:58
I've set it to
  2013-08-30 07:59:58


And testing again to add a tag  from tag-page
success

deleting tag:
success

Now I'm trying to recreate the error and see if it is happening again




--------------------------------------------------------

Old Post:

The problem is occuring when:
trying to activate/deaktivate Plugins
saving a .css in local file editor plugin
it's happening at random
after presing "back" in the browser and I retry it works without error
loosing filters in batch manager

Error:

Code:

http://www.site.com/admin.php?page=plugins&plugin=Admin_Messages&pwg_token=c78864e017a972cc863127a9a9b8be34&action=activate


"You are not authorized to access the requested page"
                    Identification Home

After reidentifing again I'm back at the Admin Home without any login issues.


The Problems started when
I had a busy server (500 error) and replaced from a  2 week old backup the all /public_html/*.php (contains admin.php, identification.php, etc).
The Backupfiles were the same size so I dont think they could be the culprit? I've also checked the permissions of the main *.php files and a few plugin folders, but they all were 644 (-rw-r--r--).

Additionally at the same time... my i.php "lost" its permissions and was set to 000 and required root-help. (which is now back to normal with its permissions)

At the same time, while working with the batch manager, 
Active Filters:Caddie, Album
when I press on "show more pictures per page" (i.e. 50 or 100 per page), then start to tag Photos in the caddie, then press "apply action", it looses half the time (but not always) all filters (Album, Tags) except caddie-filter.
Additionally it sometimes puts the tags of the few selected photos over the whole_caddie content  ( QQ )
(if this batch manager problem turns out to be unrelated I shall open a second thread, but I thought I'd mention it for more information on problem finding :) )



I've tried to
clean all cookies and cache without results.
check permissions via ftp



Sooo, quite a nifty error, but I hope its superquickandeasy to solve :P

cheers
Kyp




Active plugins:
    Add < head > element
    Akismet
    AStat.2
    Comments Access Manager
    Comments Blacklist
    Community
    Crypto Captcha
    Embedded Videos
    Grum Plugin Classes
    GThumb+
    Header Manager
    LocalFiles Editor
    Meta
    Sitemap
    SmartAlbums
    Social Buttons
    Statistics
    User Tags

plugins that were active at the time of the backup-mixup:
    pwgstuffs
    Add tags mass
    Aditional pages
    admin messages
    adv.menu manager
    autosize
    batch manager, Photo description


        Piwigo 2.5.1
        Operating system: Linux
        PHP: 5.2.17 (Show info) [2013-06-27 13:28:40]
        MySQL: 5.5.30-30.1 [2013-06-27 13:28:40]
        Graphics Library: ImageMagick 6.8.3-6

Last edited by kyp_ (2013-06-28 17:16:03)


Cheers

Offline

 

#2 2013-06-29 13:54:37

kyp_
Member
2013-06-17
84

Re: [resolved] Session cookie expires instantly (Authorization Problem)

I think I've resolved it myself. Problem did not occure again.

TL:DR
Firefox > Tools > Page Info > Permissions > Cookies > set to default /allow
in the SQL Db > Piwi_sessions > search for your cookie ID > set the Date to a high number +2 years or so..

One of the 2 above resolved my issue.

Regards
kyp


Cheers

Offline

 

Board footer

Powered by FluxBB

github twitter newsletter Donate Piwigo.org © 2002-2024 · Contact