Description
A recently introduced change caused a regression resulting in sessions not being properly invalidated.
Impact
A user that logged out of the Wire webapp, will be automatically logged in again after re-opening the application. This does not happen when:
Patches
The underlying issue has been fixed with wire-webapp version 2025-05-20-production.0.
Workarounds
This behavior can be prevented by either deleting all information upon logout as well as logging in as a temporary client (both scenarios described above).
Description
A recently introduced change caused a regression resulting in sessions not being properly invalidated.
Impact
A user that logged out of the Wire webapp, will be automatically logged in again after re-opening the application. This does not happen when:
the user is logged in as a temporary user by selecting "This is a public computer" during login or
the user selects "Delete all your personal information and conversations on this device" upon logout.
Patches
The underlying issue has been fixed with wire-webapp version 2025-05-20-production.0.
Workarounds
This behavior can be prevented by either deleting all information upon logout as well as logging in as a temporary client (both scenarios described above).