EPrints Technical Mailing List Archive

See the EPrints wiki for instructions on how to join this mailing list and related information.

Message: #10416


< Previous (by date) | Next (by date) > | < Previous (in thread) | Next (in thread) > | Messages - Most Recent First | Threads - Most Recent First

Re: [EP-tech] Forcing users to logout / closing active sessions


CAUTION: This e-mail originated outside the University of Southampton.

I love layout design,
and so will look forwards to seeing your beautiful upgraded repository
when it goes live! =D.

Yours,
Andrew.


Quoting Robin Sylvestre <robin.sylvestre@polymtl.ca>:

CAUTION: This e-mail originated outside the University of Southampton.
CAUTION: This e-mail originated outside the University of Southampton.
Hi!

Running a 3.4.1 repository that will soon be upgraded to 3.4.7.
Since generating views, abstracts, reindexing, etc. after importing
the database on the new server will likely take well over 24 hours
(possibly 48 hours), we would like to minimise the impact on users
by keeping the old server online and available for browsing, while
preventing any further changes to the database.

Ideally, users would still be able to browse the repository, but
would be unable to log in, and any existing authenticated sessions
would be terminated so that no new deposits, edits, or workflow
actions can occur while the migration is in progress. This would
allow the new server to ingest and process the archive over the
weekend without the risk of changes being made on the source system.
In EPrints 3.4.1, what is the supported way to invalidate all active
sessions and force all users to re-authenticate? Does removing the
session store invalidate both active and persistent cookie-based
sessions, or is there another session/cache mechanism that also
needs to be cleared?
I've read that EPrints 3.4.7 includes functionality to forcibly log
out all users, but that functionality does not appear to exist in
3.4.1. Has anyone tried backporting or using that mechanism on an
older 3.4.1 installation?

Our repository uses LDAP authentication through the standard EPrints
authentication hooks and Apache::Session. I'm therefore particularly
interested in understanding whether clearing session data alone is
sufficient to force all users out, including those authenticated via
persistent cookies.

Thank you for your input!

I'm looking forward to showing you our new version. I've put a lot
of work into it, and I'm quite proud of the result! I humbly believe
it will be the most beautiful EPrints repository in the world! 😄
Going live in October! 🎉 🤩

Robin


[cid:image001.png@01DD3701.625BC7E0]
ROBIN SYLVESTRE
Technicien des systèmes informatisés
Bibliothèque
514-340-4711 | poste 5973

Polytechnique Montréal
2500, chemin de Polytechnique
Montréal, Québec, H3T 1J4