1971

Prev Next

User unable to login to SES Web with valid password following same account session being timed-out and automatically logged out.

If a user remains logged in but inactive on a SESWeb console session, that user can be logged out automatically once a time-out threshold has been breached.  Users find that they are unable to log in again without being prompted to enter a verification code. 

Affected Versions. 9.0 SR2

Scenario: 

1. A user logs in to the SESWeb console and leaves the session idle until it is auto logged-out due to being open/idle beyond a permitted threshold
2. The user attempts to login again with a valid password

The user would expect to be able to log in successfully but …
The user is instead required to login again, but this time must enter a verification code (like what happens if the user enters incorrect credentials.)


Workaround:

There is an anti-forgery token that will expire if the user does not login within a certain time.

Refresh the web page by tapping F5, then enter a valid password. The user should then be able to login successfully, without encountering the requirement to enter a verification code.