0030031: row created in ad_session for same cookie after every erp logout
Context of testing:
[2:56:18 PM] Stefan Huehner: create ad_session with status F
[2:56:25 PM] Stefan Huehner: if you login that same row changes to status S
[2:56:44 PM] Stefan Huehner: if you logout that row changes to session_active=n
[2:56:49 PM] Stefan Huehner: browser shows login page
[2:57:05 PM] Stefan Huehner: and on top you get 2 more rows in ad_session with that same for 'websession' and status = F again

This but is about that last line.
Having active erp login
Doing normal logout (which redirects to login page)
Does create 2 ad_session entries for same cookie (aka column websession)
Go to livebuilds. erp_pgsql_pi

now check ad_session content related to your logins (i.e. filter by your ip)
select ad_session_id,created,websession,remote_addr, username,login_status,* from ad_session where remote_addr = '<your client ip>' order by created desc limit 3;

An sql similar to that can be used to find the probably relevant rows assuming single user.

Note: livebuilds is example, probably reproducible in other systems (i.e. also noticed in online demo)
2015-06-11 09:04   
(edited on: 2017-05-17 09:16)
The behavior seems to be different depending on the browser.

 - Firefox: in this case, when logout is done, the code in index.jsp is called twice and therefore the authenticate method of AuthenticationManager is executed two times. For this reason, a double row with status "F" is created in ad_session table.

 - Chrome: in this case, when logout is done, one record is created with status "F". This is also wrong.

2017-05-30 15:20   
Repository: erp/devel/pi
Changeset: 624c1fa5299c05dd0de944b06e65e33b3a7da6a9
Author: Asier Lostalé <asier.lostale <at>>
Date: Tue May 30 15:17:57 2017 +0200
URL: [^]

fixed bug 30031: row created in ad_session for same cookie after erp logout

  Logout navigates to root page (index.jsp) which in case of not logged in,
  redirects to login page.

  By default jsp pages creates a HttpSession if it does not exist, so finally
  we got a HttpSession + an AD_Session entry.

  Fixed by preventing session creation in index.jsp, and redirecting to login
  page if no session detected.

M src/index.jsp
M src/org/openbravo/authentication/
2017-05-30 20:59   
A changeset related to this issue has been promoted main and to the
Central Repository, after passing a series of tests.

Promotion changeset: [^]
Maturity status: Test
2017-06-02 18:22   
Code reviewed + tested OK.