I am encountering a critical issue related to Broken Session Management in our application, specifically with session invalidation after logout when using Firefox browser.
Issue Description: After logging out, if the user clicks the browser's Back button, they are automatically logged back into the application without needing to re-enter credentials. This clearly indicates that the session is not being properly invalidated.
Root Cause: Upon investigation, it appears that the .AspNetCore.Identity.Application cookie — which manages the authentication session — is not being cleared correctly in Firefox. Despite attempting to forcibly clear this cookie programmatically, the issue persists specifically in Firefox, whereas other browsers behave as expected.
Impact: This behavior poses a significant security risk, potentially allowing unauthorized access to protected resources after logout, compromising session integrity.
I have attached a screenshot demonstrating this behavior for your reference.

20 Answer(s)
-
0
Hi @kansoftware
Thank you for your feedback. We've created an issue for this issue. You can follow the developments here.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @kansoftware
The issue you mentioned has been fixed with this pull request. Could you please check if the issue is resolved on your end after applying this change? Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
I tried the above code, but it didn’t resolve my problem. I’m still getting logged in when clicking the browser’s back button after logging out.
The mentioned code is only related to the SignalR chat functionality in JavaScript and is not linked to any cookies or authentication process.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @kansoftware
After applying the change made in the chat.signalr.js file, did you run the project and apply the hot reload and bundle creation operations?
If you want to create new bundles before publishing the project, you can run the
yarn create-bundlesornpm run create-bundlescommand in the terminal under theWeb.Mvcproject.After publishing the project, can you run "Ctrl+Shift+R" command to hot reload in the browser?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Yes, I have completed all the tasks mentioned above. I ran the project, applied hot reloading, and performed the bundle creation operations. Additionally, I did a hard refresh in the Firefox browser.
But still facing same issue
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @kansoftware
Thank you for your feedback. We will investigate this situation in detail. I will let you know once a resolution is reached. Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[oguzhanagir] said: Hi @kansoftware
Thank you for your feedback. We will investigate this situation in detail. I will let you know once a resolution is reached. Thank you.
Hi, Just following on this, is there any progress on this? Did you also able to replicate this issue
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @kansoftware
After this fix, we haven't been able to replicate the issue you described. Could you clear all stored information, such as cookies and storage, in the Firefox Storage section and try again? Could you even try this in an incognito tab?
Video to reproduce the problem I shared a video with you to make sure I'm following the steps correctly.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
I tried using a fresh installation of AspNet Zero version 13.0.0, but I’m still facing the same issue.
I ran the application locally on my machine and logged in as a host user using the Firefox browser. After logging out and then clicking the browser’s Back button, I was automatically logged back in without having to re-enter my credentials.
Upon inspecting the browser cookies, I noticed that the .AspNetCore.Identity.Application cookie is not being cleared after logout. Based on my findings, this cookie appears to be causing the issue.
Additionally, I have implemented the changes in chat.signalr.js as suggested in the trial ticket, but the issue persists.
I’ve attached a video for your reference.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @kansoftware
After applying this fix, we can't reproduce the issue. There may be a different change on your end. Could you please email your project to [email protected] so we can quickly understand this?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
We have shared the project via the email.
Please let us know if you encounter any issues accessing it or need any additional details to reproduce the problem.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @kansoftware
We have successfully downloaded your project. Thank you for sharing it with us. We are currently reviewing the issue and will contact you through this support ticket for a resolution as soon as possible. Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi team, Could you tell me how this issue has been resolved? I'm also experiencing a similar problem. If it has been resolved, please provide me with your solution. Thank you
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @trungbttsd
The issue you mentioned has been fixed with this pull request. Could you please check if the issue is resolved on your end after applying this change? Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi team, I followed the instructions in the pull request, but the issue still persists. You can reproduce the error using the following steps: Download ASP.NET Core MVC & jQuery v14.3.0. Modify the code according to the pull request (specifically the chat.signalr.js file). Use the latest version of Firefox 148.0.2 (64-bit). Then reproduce the issue with these steps: Log in to the system. Log out using the logout button. When the page redirects to the login screen, log in again immediately without pressing F5. Repeat the login/logout process several times. After several attempts, the error will appear. Thank you for your support. I hope the information provided helps you identify and fix the issue.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @trungbttsd
After updating the "chat.signalr.js" file for a quick check, did you run the create-bundle and miniy commands? "npm run create-bundles" or "yarn create-bundles". After running this command and clearing your browser's session information, could you try again and see if this problem persists?
We will thoroughly investigate this issue based on your description. However, this problem does not occur in the latest version.
Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi, I reran npm run create-bundles and cleared the browser cache, but the issue still persists. If it helps, I can record a short video showing the full process (building bundles and reproducing the error). Please let me know. Thanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @trungbttsd
We tried to reproduce the issue and the steps you described in our development environment (v15.2) on several different devices, but we could not encounter the problem as described. When we tested the same steps using the version you mentioned (v14.3), we encountered an Antiforgery error.
To resolve this issue, we recommend upgrading your project to v15.2-RC-1. If you prefer to remain on v14.3, you can resolve the issue by applying the steps below.
Main Issue (Antiforgery Token + XML Parse Error) File:
Controllers/AccountController.cs— line 295public async Task<ActionResult> Logout(string returnUrl = "") { await ClearGetScriptsResponsePerUserCache(); // ← ADDED await _signInManager.SignOutAsync(); ... }Reason: After the logout operation, the browser reloads the Login page. However, since the per-user script cache is not cleared, the
AbpScripts/GetScriptsendpoint is called with a stale key belonging to the previous user and returns an HTML/redirect response. The browser then attempts to parse this response as JavaScript, which results in an “XML parse error.” At the same time, the antiforgery token still belongs to the previous user, leading to an AntiforgeryValidationException.If the issue persists after applying these steps, a video recording demonstrating the problem would be very helpful for us to reproduce it. Could you please send the video to [email protected] so we can investigate the issue in more detail?
Additionally, if there are any error logs generated under the MVC project or any browser console errors, sharing them would also help us identify the root cause of the issue.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi team, I tried the steps you provided, but the issue still persists. I haven't had time to record the video yet today, but I will record it and send it to you as soon as possible so you can review the issue. Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @trungbttsd
Thank you for your update.
No problem at all, please feel free to share the video whenever it’s convenient for you. Once we receive it, we’ll review the issue in detail and provide you with further guidance as soon as possible.
Thank you
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)