Skip to main content
October 15, 2012
Question

CFTOKEN PROBLEM IN CF10

  • October 15, 2012
  • 3 replies
  • 7500 views

Hi,Irecently installed Coldfusion 10.When i login from first browser it logs me in and when i try to login from another browser it is throwing me out that there is active session which doesnt happen in CF9.I noticed that CFTOKEN is not genearating new token when i try login from second browser.Any Help would be appreciated.

    This topic has been closed for replies.

    3 replies

    BKBK
    Braniac
    October 16, 2012

    @Mucharla,

    Go back to the bug report, and scroll down to the post by Hemant Khandelwal. He gives a workaround, involving the Java flag

    -Dcoldfusion.session.protectfixation=false

    October 16, 2012

    Hi BKBK,

    can you please let me know where exactly bug report means.

    regards

    raja.

    BKBK
    Braniac
    October 16, 2012

    Mucharla Raja wrote:

    can you please let me know where exactly bug report means.

    You will find the bug report at the link that Adam Cameron gave above. You have to include the flag in the 'Java and JVM' field in the ColdFusion Administrator.

    Inspiring
    October 15, 2012

    Yes, this is a new (and somewhat hamfisted/misguided in its implementation) "feature" of CF10.  I think it only comes into play if you select the "secure profile" option when installing though?  I dunno how to switch it off.

    I recommend voting to get this reverted back to the default behaviour of CF prior to CF10, and the new feature made optional.

    Details here:

    https://bugbase.adobe.com/index.cfm?event=bug&id=3339008

    --

    Adam

    October 15, 2012

    hi Adam Cameron.,

    can you give any quick solution for this as this needs to tide up soon.

    regards

    raja.

    Inspiring
    October 15, 2012

    Yes, the solution was to not install the secure profile in the first place.  As to solve it after the fact: I have no idea.  I've never had to deal with it.

    If you're in a hurry, you should be soliciting paid-for support from a consultant, not asking questions on a community-based forum.

    --

    Adam

    Braniac
    October 15, 2012

    CF10 lets only one cfide/administrator at a time.
    See section - There are however some behavioral changes:
    http://www.adobe.com/devnet/coldfusion/articles/security-improvements.html

    HTH, Carl.

    October 15, 2012

    hi carl,

    Can you breif me about the possibility of logging into two different browsers with out duplicating the cftoken .

    Can we login to two browsers in CF10?

    Braniac
    October 15, 2012

    Hi Raja, CFadmin by design in CF10 only allows 1 admin login at a time. I guess you could add multiple users. EG

    HTH, Carl.