Skip Navigation
Temporarily Logged In As Another User - Potential Security Issue?

Hey everyone! I just had something rather weird and concerning happen. While browsing Lemmy through the default web interface, I clicked on a post link and got the usual server error. I refreshed the page and got the same thing. Then, I refreshed a second time and while the post loaded, I was a bit perplexed as my Lemmy theme was completely different. I thought that was weird, so I decided to go Settings. That's when I realized that the username in the top right corner was not my own. Instead of "Shrinra", it showed "aeharding"! I clicked the link for Settings just to see what would happen, and thankfully, it threw me out of the session entirely. In fact, my actual session was gone and I had to log back in.

A part of me thinks I am crazy. Has anyone else experienced this? If so, it is a known security issue? It is more than a bit concerning to think that someone else may be able to access someone else's session just by navigating to a certain page.

Thanks!

9
What password manager do you use ?
  • I currently use Strongbox on macOS and iOS. While it is definitely a product tailored to more advanced users, it is still easy to use IMO, and there's currently no better option for those who want a native Mac app built exclusively for the Mac. There's no proprietary cloud storage like popular commercial password managers (you can use iCloud, OneDrive, Dropbox, WebDAV, transfer over your local network, etc.), and it uses KeePass, so there is no lock in either. Additionally, if you suffer from subscription fatigue, there's an option to purchase a lifetime license. I love it, and would recommend the product to those who are on Apple platforms. It doesn't have all of the features of 1Password just yet, but the developer is very responsive, and it is getting better all of the time.

    I switched over from 1Password, as I was not very impressed with the direction they were heading. 1Password 7 is better in every way compared to 1Password 8, IMO. Also, moving from AppKit to Electron for their Mac app was simply not acceptable to me either, and there was no way I was ever going to pay an annual subscription for the "pleasure" of using it. I only ever paid up because of their high quality apps, and when that was no longer the focus, I was out.

  • InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)SH
    Shrinra @lemmy.world
    Posts 1
    Comments 2