Skip to main content

Products.NoDuplicateLogin

Project description

This PAS plugin will reject multiple logins with the same user at the same time. It ensures that only one browser may be logged with the same userid at one time.

Implementation

The implementation works like this: Suppose that Anna and Karl are two people who share a login annaandkarl in our site. Anna logs in, authenticating for the first time. We generate a cookie with a unique id for Anna and remember the id ourselves. For every subsequent authentication (i.e. for every request), we will make sure that Anna’s browser has the cookie.

Now Karl decides to log in into the site with the same login annaandkarl, the one that Anna uses to surf the site right now. The plugin sees that Karl’s browser doesn’t have our cookie yet, so it generates one with a unique id for Karl’s browser, remembers it and forgets about Anna’s cookie.

What happens when Anna clicks on a link on the site? The plugin sees that Anna has our cookie but that it differs from the cookie value that it remembered (Karl’s browser has that cookie value). Anna is logged out but the plugin and sees the message “Someone else logged in under your name”.

Installation

Add Products.NoDuplicateLogin to the eggs parameter of your plone.recipe.zope2instance section:

[plone]
recipe = plone.recipe.zope2instance
eggs =
    Plone
    ...
    Products.NoDuplicateLogin

Now run buildout and restart Plone.

History

1.0a1 (12/17/2010)

  • Add test harness [aclark]

  • Rip out “experimental” session storage, too many ZODB conflicts. [aclark]

  • Plone 4 compat [aclark]

  • Re-package as egg [aclark]

1.0 svn/dev

  • Plone 3 compat [perrito]

  • Original implementation [nouri]

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Products.NoDuplicateLogin-1.0a1.zip (18.3 kB view details)

Uploaded Source

File details

Details for the file Products.NoDuplicateLogin-1.0a1.zip.

File metadata

File hashes

Hashes for Products.NoDuplicateLogin-1.0a1.zip
Algorithm Hash digest
SHA256 635dfe5f19102f8c3ebfe5b0d0a3554a376d57d9eb22540af30ad8ff59ab674e
MD5 46f924c5684627cc6b0facafc01c07aa
BLAKE2b-256 bfd6350a5f87dafe0d48625ac464e7c52b715dfc896f5f2a36a48a788e312e2d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page