Users switching sessions

Hello! I have the latest version of the Frappe Framework with the Helpdesk and Wiki modules installed in a Ubuntu server in cloud. It is being used as an IT support application for our company, and we have SSO with Microsoft setup and working.

My problem is that, seemingly at random (as I cannot replicate it at will), an agent will switch logged users. This means that, upon loading up a Ticket or going back to the Ticket List or accessing any other page within Frappe, their session will be replaced by another one.

I cannot say that this ONLY happens between agents, but those are the confirmed cases so far.

Either way, this is a VERY PROBLEMATIC issue, as it’s not only rather annoying that every time it happens they have to log out of the other account and log back in with theirs, it also poses an enourmous secutiry risk, as people who shouldn’t have permissions can suddenly be in an account with said permissions.

I’ve seen a few other topics open about this problem but they are old and remain unanswered. Does anyone else have this issue, and does anyone know how to make it stop?

1 Like

Are you sure all frappe users have a Microsoft 365 user license for MS Entra ID?

I agree this is a broken security model. What operating system and browser are
the clients using? Do they share computers? If they share computers do they
have unique user accounts. Do any of these users share a browser login to
sync bookmarks and cookies?

It would be interesting to browse to office.com and see which user account
is logged in (prior to logging out of the ghost account).

2 Likes