[GDPR] | Invite to a role - Logged in user, warning popup is not matching designs and session Hijacking creates security risk and problems during workflow #11021
Labels
Bug:3:Critical
A bug that prevents a substantial majority of users from using the software.
Milestone
Valid Title
Description
This one has two issues. First one is the popup is not rendering variables correctly and does not match the Figma design which forces logout. But the more concerning problem is the session tokens can be hijacked which causes a security issue and leads to further problems for the workflow.
Steps to Reproduce
Expected Result
Figma designs have a separate modal (see screenshot). Beyond that the user should not be able to continue with the workflow without having been signed out initially.
Actual Result
See screenshot. Several broken popups throughout the workflow. User is able to bypass them and continue.
Environment Details
No response
Application Version
OJS stable-3_5_0
Logs
No response
Additional Information
PRs
[pkp-lib][main]: #11055
The text was updated successfully, but these errors were encountered: