- Status Closed
-
Assigned To
cbay - Private
Opened by parthsolankih9 - 26.09.2026
Last edited by cbay - 29.09.2026
FS#506 - Webmail session remains authenticated after logout (session not invalidated)
Severity suggestion: Medium
Affected service: https://webmail.alwaysdata.com (exact in-scope hostname)
Description
After a user logs out of the webmail (?_task=logout, the link the UI itself offers: ./?_task=logout), the platform session cookie remains fully authenticated. A subsequent request to /roundcube/?_task=mail returns the user's live inbox without any re-authentication, and a request to the webmail root (/) immediately redirects back to /roundcube/?_task=mail — the proxy layer re-establishes the Roundcube session from its stored state. Logging out therefore does not end the session.
Steps to reproduce (standard Linux tools only, per program guidelines)
1. GET https://webmail.alwaysdata.com/ — obtain CSRF cookie and csrfmiddlewaretoken.
2. POST https://webmail.alwaysdata.com/ with csrfmiddlewaretoken, login=<mailbox>, password=<password> → 302 to /roundcube/?_task=mail; a platform session cookie is set.
3. GET /roundcube/?_task=mail&_mbox=INBOX → 200, <title>webmail :: Inbox</title> (pre-logout confirmation).
4. GET /roundcube/?_task=logout → 200 logout page (request is processed).
5. GET /roundcube/?_task=mail&_mbox=INBOX with Cache-Control: no-cache → 200, <title>webmail :: Inbox</title>, fully authenticated mailbox view.
6. GET https://webmail.alwaysdata.com/ → 302 back to /roundcube/?_task=mail — session re-established automatically.
Steps 5–6 reproduced on a fresh session, twice (initial observation plus a controlled retest), with cache-busting headers — this is not a cached-page artifact.
Impact
- A user who logs out on a shared or compromised machine believes their mail session has ended. Any party who captured the session cookie retains full mailbox access indefinitely — the standard mitigation ("log out") does not invalidate the credential.
- The mailbox receives alwaysdata's own password-reset and account emails, so persistent mailbox access also means persistent reachability into the account-recovery flow of the platform.
Test account note
Testing was performed with a dedicated test account that I own and control; I can re-verify against a patched build on request. (Please keep this report free of the test credentials — happy to share them privately if useful for triage.)
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Hello,
I cannot reproduce the issue. The roundcube_sessauth cookie is properly removed on logout. Can you provide a script that exhibits the problem?
Kind regards,
Cyril