News:

SMF 2.1.4 has been released! Take it for a spin! Read more.

Main Menu

Bizzarre user logins etc...

Started by stompbox, April 28, 2018, 02:00:49 PM

Previous topic - Next topic

stompbox

After moving to a new server and also updating from 2.0.14 to 2.0.15, users have been seeing themselves being banned, or logged in with someone else's profile. This is all temporary as a click to read the forum etc... will correct itself. I myself have been logged in as someone else. It's usually the last person logged in.

I don't remember this happening with 2.0.14 but I have also changed servers.
Any ideas on what this might be. It seems to persist - day to day with different users. It's somewhat harmless in that it fixes itself, but any ideas appreciated.

vbgamer45

What is your caching settings set at in smf under server settings
Community Suite for SMF - Take your forum to the next level built for SMF, Gallery,Store,Classifieds,Downloads,more!

SMFHacks.com -  Paid Modifications for SMF

Mods:
EzPortal - Portal System for SMF
SMF Gallery Pro
SMF Store SMF Classifieds Ad Seller Pro

Illori

usually this is an issue with server side cache like varnish, you would need to ask your host to disable it for your account.

stompbox

QuoteWhat is your caching settings set at in smf under server settings

Caching level: No Caching
memcache settings: blank

Illori

then as i said above you need to reach out to your host.

vbgamer45

I agree yes server config issue.
Community Suite for SMF - Take your forum to the next level built for SMF, Gallery,Store,Classifieds,Downloads,more!

SMFHacks.com -  Paid Modifications for SMF

Mods:
EzPortal - Portal System for SMF
SMF Gallery Pro
SMF Store SMF Classifieds Ad Seller Pro

stompbox

OK they said there is no caching. Any other ideas? Thanks

: There is no caching plugin installed. The caching plugin is available on the server but its only for Wordpess and your forum is not wordpress.

Illori

then they are lying to you. the only way for this to happen is with the use of server side caching.

GigaWatt

Do you have a backup of the 2.0.14 version? Of you do, test if this happens with the 2.0.14 version... although, as Illori posted, I doubt the problem will disappear with rolling back to 2.0.14. Don't roll back the database, only the files.
"This is really a generic concept about human thinking - when faced with large tasks we're naturally inclined to try to break them down into a bunch of smaller tasks that together make up the whole."

"A 500 error loosely translates to the webserver saying, "WTF?"..."

Aleksi "Lex" Kilpinen

Nothing between .14 and .15 changes in a way that would cause that. All the symptoms described are however familiar symptoms of a badly configured server side cache, such as Varnish.
Slava
Ukraini!
"Before you allow people access to your forum, especially in an administrative position, you must be aware that that person can seriously damage your forum. Therefore, you should only allow people that you trust, implicitly, to have such access." -Douglas

How you can help SMF

GigaWatt

Yeah, I know... what I suggested was an attempt to persuade the OP that the problem is not the update itself, but a server side problem ;).
"This is really a generic concept about human thinking - when faced with large tasks we're naturally inclined to try to break them down into a bunch of smaller tasks that together make up the whole."

"A 500 error loosely translates to the webserver saying, "WTF?"..."

stompbox

Does this help at all?
(from a user)
I was logged in
1) I tried to post something and it was taking ages to post.  So I clicked on the forum link to move on.
2) I then became another user
3) I clicked a forum link again and I became banned but it reported me as a Guest.
4) I looked at my cookies and saw three cookies:
    SMFCOOKIE923    which contained a long string with "percent coded" numbers etc.
                                 which decoded to something like  a:4:{i:0;s:3:"160"; ...
    PHPSESSIONID
    SMFCOOKIE923_  which contained 480

5) The SMFCOOKIE923_ looked dodgy so I deleted it.  Then on the next click I was not banned and I was still logged in as myself.   I posted this so it must be working!.
-----------
Edit: I logged out and logged in and I do not see the "SMFCOOKIE923_" cookie.

GigaWatt

Is that the cookie name of your forum (SMFCOOKIE923)? Have you tried changing it to something more adequate (not leave it so generic)? For example, if your forum is about horses and your URL is ponysandhorses.com, your cookie name should be something like "ponhorse"... or something along those lines.
"This is really a generic concept about human thinking - when faced with large tasks we're naturally inclined to try to break them down into a bunch of smaller tasks that together make up the whole."

"A 500 error loosely translates to the webserver saying, "WTF?"..."

Aleksi "Lex" Kilpinen

Do contact your host and make them double check Varnish is not active on your account.
Slava
Ukraini!
"Before you allow people access to your forum, especially in an administrative position, you must be aware that that person can seriously damage your forum. Therefore, you should only allow people that you trust, implicitly, to have such access." -Douglas

How you can help SMF

lurkalot

Varnish doesn't show up on that site from what I can see.  But if I have the correct site, it appears to be running wordpress as well which I believe can cause problems when running together, depending on how they are set up.

Kindred

oh yeah... if you have SMF running in a subdirectory to WordPress, then all sorts of bizarre things can happen, because WordPress (being the hog that it is) assumes that it is the only script running on the site and intercepts everything.

IIRC< it requires a modification to the wordpress default htaccess
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

stompbox

No Wordpress is in its own directory off of the public_html. I can try changing the cookie name. I left it with that name because repair_settings had it as the default.
I can try changing it but it seems like that wouldn't fix the problem.
What if I actually turned caching ON in the server setting for SMF?

Aleksi "Lex" Kilpinen

The cache in SMF is not a similar type of cache, it doesn't keep whole rendered pages in memory like Varnish does. SMF only holds some data it would otherwise repeatedly query from different sources. I'd say turning it on should have no effect really.
Slava
Ukraini!
"Before you allow people access to your forum, especially in an administrative position, you must be aware that that person can seriously damage your forum. Therefore, you should only allow people that you trust, implicitly, to have such access." -Douglas

How you can help SMF

stompbox

Thanks! The mystery continues along with people being listed as being banned as well now. If they delete cookies, it all works.

GigaWatt

Have you changed the cookie name?
"This is really a generic concept about human thinking - when faced with large tasks we're naturally inclined to try to break them down into a bunch of smaller tasks that together make up the whole."

"A 500 error loosely translates to the webserver saying, "WTF?"..."

Advertisement: