Page MenuHomePhabricator

User account in an undisturbed session occasionally logs out
Closed, DeclinedPublic

Description

Author: syrthisswiki

Description:
A few times on en.wiki now, I will visit a page and either upon arrival at the page or upon browsing away from the page will find myself logged out. I don't have a measure of what types of pages, tho anecdotally I think it is both userpages and articles. I did a search of current bugs and didn't see one that described this, so apologies if its already known.

This is minor, but troubling as it could expose a users underlying ip (as it did today to me, when I hadn't noticed it happening). I had to delete the page and restore selected revisions to hide the edit and prevent outing.


Version: unspecified
Severity: minor

Details

Reference
bz23295

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 10:59 PM
bzimport set Reference to bz23295.
bzimport added a subscriber: Unknown Object (MLST).

syrthisswiki wrote:

Happend again just now, after an edit conflict.

matthew.britton wrote:

The following things will (I believe) cause you to be logged out, check that it isn't one of these:

  • Login session expiring, if you didn't select "remember me" when logging in
  • Login token expiring even if you do select "remember me" (eventually, takes a long time though)
  • Having your browser or a system cleaning tool of some sort set to automatically clear your cookies periodically / after a certain time
  • Going into "private" mode (or whatever your browser calls it)
  • Logging out of the account while using a different browser or an editing tool, or logging out of a different Wikimedia project -- under unified login, this will log out your account everywhere, on all browsers and wikis

I'm assuming from your comments that it is actually logging you out, not merely displaying pages as if you were not logged in (which can be caused by caching mishaps).

Also, "outing"? Unless you have your own personal static IP address, all anyone can figure out from it is your ISP.

syrthisswiki wrote:

I only edit from work, and the ip is static.

Yep, its definitely logging me out but I hadn't considered that it might be my browser clearing cookies. In general, I have at times edited en.wiki from my desk for 6+ hours without being logged out (I don't click remember me, though) so I don't know what would have changed recently to cause it to happen at the random short intervals.

syrthiss, do you have more clues on how/when this is happening?
I've been seeing this happen (although not to me) for other users who also had a static IP, coincidence or not.

This (looking at the dates) is unrelated to the frequent logouts incident of a short while ago and also to the suspect that some users get logged out after new releases deployments on Wikimedia projects.

Note that if confirmed this would perhaps be more than a "minor" bug in the opinion of some, because logged out edits often qualify for revision deletion of the username in the opinion of privacy-caring users and of sysops/oversighters on some of our wikis, and apparently the warnings that you're editing as IP are not enough.

syrthisswiki wrote:

(In reply to comment #4)

syrthiss, do you have more clues on how/when this is happening?

I do not. It ceased happening to me sometime not too long after I logged this (maybe June or July 2010), and hasn't happened since. Sorry. :(

(In reply to comment #5)

(In reply to comment #4)

syrthiss, do you have more clues on how/when this is happening?

I do not. It ceased happening to me sometime not too long after I logged this
(maybe June or July 2010), and hasn't happened since. Sorry. :(

Marking this bug as WFM then, as this issue is no longer reproducible.

(In reply to comment #6)

Marking this bug as WFM then, as this issue is no longer reproducible.

False:

(In reply to comment #4)

I've been seeing this happen (although not to me) for other users who also had
a static IP, coincidence or not.

As I don't have further elements, it would be pointless to open another bug.

I tested this and I was never logged out.

Lukeyhano lowered the priority of this task from Medium to Low.
Lukeyhano set Security to None.
Aklapper changed the task status from Resolved to Declined.Dec 30 2014, 7:50 PM
Aklapper claimed this task.

@Lukeyhano: Do you have a static IP address? That was mentioned here by folks who experienced this problem. If you don't have I'd rather reopen this task, plus the title say "occasionally" so it would be good to know how long you tested this, and on which web site (I assume en.wikipedia.org)?

But in any case I'm changing the status to "Declined" here instead of "Resolved" - see https://www.mediawiki.org/wiki/Bug_management/Bug_report_life_cycle

Anybody feel free to reopen this ticket if this problem still happens.