WPIntell

Source evidence

Session Mixed

Persistent Login · review · 2024-10-25T12:38:00+00:00

complaintsentiment
mediumseverity
0.86relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

8 / 34 rows with source links

23.5% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

review · 1 stars
amfahadsafi unresolved
Session of different user mixed after installing this plugin, like the admin session were also mix with user session and user got admin privileges. can you check this issue. i will update the rating depend on your response Hi there, Thank you for using Persistent Login. On install Persistent Login doesn’t change any sessions or session data, I can’t see how this could have been caused by Persistent Login. Can you explain how you know that user sessions have been altered and users given incorrect permissions? Persistent login uses the default wordpress login session logic, it simply extends the expiry time of the session. We only alter session expiry times after a user has been authenticated with a WordPress hook that provides the authenticated users ID. This ensures we’re updating the correct users session. You have left a review rather than a support request, are you looking for support with this issue? If so I would recommend posting in the appropriate place. Thanks, Luke i have verified it multiple times my site showing issue using persistent login plugin! when a user with subscriber role got login they login automatically as my admin ID For the record, I tried to provide support for this user via the correct channel, but they stopped responding. Support thread: https://wordpress.org/support/topic/session-mixed-2/

Comments

3 shown
lukeseager 2024-10-26T07:17:00+00:00

Hi there, Thank you for using Persistent Login. On install Persistent Login doesn’t change any sessions or session data, I can’t see how this could have been caused by Persistent Login. Can you explain how you know that user sessions have been altered and users given incorrect permissions? Persistent login uses the default wordpress login session logic, it simply extends the expiry time of the session. We only alter session expiry times after a user has been authenticated with a WordPress hook that provides the authenticated users ID. This ensures we’re updating the correct users session. You have left a review rather than a support request, are you looking for support with this issue? If so I would recommend posting in the appropriate place. Thanks, Luke

amfahadsafi 2024-10-30T08:12:00+00:00

i have verified it multiple times my site showing issue using persistent login plugin! when a user with subscriber role got login they login automatically as my admin ID

lukeseager 2025-02-09T19:54:00+00:00

For the record, I tried to provide support for this user via the correct channel, but they stopped responding. Support thread: https://wordpress.org/support/topic/session-mixed-2/