-
Notifications
You must be signed in to change notification settings - Fork 587
Description
Short description: When a non-admin user assigns a ticket to an admin user, any active session for the admin user assumes the identity of the non-admin user.
We were able to replicate this issue many times. The users are on two separate workstations, and have not logged in to each other's workstation. I have attached a video that shows the identity swap. Any information for troubleshooting would be appreciated. We intend to implement LDAP authentication, which may fix the issue, but we want to verify that there won't be a potential swap of a non-admin user to become an admin user before we implement LDAP.
freescout_identity_vid.mp4
PHP version: 8.2.16
FreeScout version: 1.8.120 >> 1.8.122 (We updated when we noticed the problem. Problem persists.)
Database: MySQL
Are you using CloudFlare: No
Docker: Yes
LDAP: No