Skip to content

Sensitive Info is exposed when clicking the back button after logging out. #1

Description

@GKARLOZ

Contributing as a tester reporting bugs.
Not sure on what repository to leave this issue.

Description:

Potential security risk of sensitive information being exposed such as API keys.

If a user decides to log out from the API page, the tokens can be seen and copied by pressing the back button on the browser without logging back in.

Environment:

  1. Windows 10
  2. Chrome Version 120.0.6099.225

Preconditions:

  1. Open the Application (https://openweathermap.org/) in Chrome Browser.
  2. User is logged in.

Steps to reproduce

  1. Click on the Dropdown menu next to the username.
  2. Select "My API keys" .<Verify ER -1>
  3. Click on the Dropdown menu next to the username.
  4. Select "Logout" option <Verify ER -2>
  5. Click on Browser back button <Verify ER -3>

Expected result

  1. User should see the API keys page.
  2. User should be taken to the login page and a red alert message should appear displaying "You need to sign in or sign up before continuing".
  3. User should not get logged in nor should sensitive information be shown.

Actual Result:

  1. User appears to be logged in and API keys can be copied.
issue1.1.mp4

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions