• Resolved delaitec

    (@delaitec)


    The plugin does not log out

    Which brings up serious security issues.

    After logging in with the Google account on a device.
    And then click LOGOUT.

    It just seems to have logged out, but in fact it didn’t because when trying to log in again by clicking on the google icon the plugin logs in without requiring a password.

    That is, on the first login, it asks for the password, and saves the login in BROWSER.
    And when you click on exit, the Browser continues with the login saved.
    Which allows another person who has access to the browser to log in just by clicking on the google icon, having undue access to the account of the first person.

    The only way to log out is to clear the browser cache completely.
    Which is extremely inconvenient.

    This brings up several security issues such as:
    01 – If we log in to someone else’s device, our login will remain there saved even after leaving.
    02 – After logging in with the first google account, it is not possible to switch accounts, choosing a second one, as the plugin will always automatically log in with the first account logged in.

    Do you have a forecast for when you will resolve this issue?

    Or at least, give the user the option to click on the login button, choose whether to use the last logged in account, or use a second google account?

    The Nextend Social Login plugin also does not log out of google accounts.
    However, when trying to log in again, it allows you to choose whether you want an account already logged into the browser, or to use another account.

    https://wordpress.org/plugins/nextend-facebook-connect/

Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
  • The topic ‘Does not allow logging in if the browser is already logged in’ is closed to new replies.