Skip to content
This repository has been archived by the owner on Aug 1, 2022. It is now read-only.

PMM-1986: Signing out with HTTP auth enabled leaves the browser "signed in" #45

Merged
merged 1 commit into from Jan 29, 2018
Merged

PMM-1986: Signing out with HTTP auth enabled leaves the browser "signed in" #45

merged 1 commit into from Jan 29, 2018

Conversation

cezmunsta
Copy link
Contributor

When HTTP authentication is enabled, the Grafana "sign out" does not work as expected, with navigation to any page other than the login page afterwards providing the user with immediate access once more.

This could leave end-users believing that they have signed-out and perhaps provide unauthorised users with access.

Using the nginx location directive to specifically handle the logout page for Grafana, we can force the browser to reauthenticate if HTTP authentication is enabled.

@CLAassistant
Copy link

CLAassistant commented Jan 27, 2018

CLA assistant check
All committers have signed the CLA.

@AlekSi
Copy link
Contributor

AlekSi commented Jan 29, 2018

LGTM. @cezmunsta, can you please sign our CLA? Just click a button in the message above.

@AlekSi AlekSi merged commit 9a02355 into percona:master Jan 29, 2018
@cezmunsta cezmunsta deleted the issues/PMM-1986 branch September 16, 2021 14:16
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
4 participants