diff --git a/application/loginwebpage.class.inc.php b/application/loginwebpage.class.inc.php index 2355ff847..515ed00f1 100644 --- a/application/loginwebpage.class.inc.php +++ b/application/loginwebpage.class.inc.php @@ -369,16 +369,7 @@ class LoginWebPage extends NiceWebPage public static function ResetSession() { // Unset all of the session variables. - Session::Unset('auth_user'); - Session::Unset('login_state'); - Session::Unset('can_logoff'); - Session::Unset('archive_mode'); - Session::Unset('impersonate_user'); - Session::Unset('PluginProperties'); - Session::Unset('UrlMakerClass'); - Session::Unset('itop_env'); - Session::Unset('obj_messages'); - Session::Unset('profile_list'); + Session::UnsetAll(); UserRights::_ResetSessionCache(); // If it's desired to kill the session, also delete the session cookie. // Note: This will destroy the session, and not just the session data! diff --git a/sources/Service/Session/Session.php b/sources/Service/Session/Session.php index 6eb96ab03..2fdb494ee 100644 --- a/sources/Service/Session/Session.php +++ b/sources/Service/Session/Session.php @@ -131,6 +131,19 @@ class Session } } + /** + * Unset all session variables, no matter if they were set by iTop or not + * + * @return void + * @since 3.3.0 N°9625 + */ + public static function UnsetAll(): void + { + foreach (self::ListVariables() as $sKey) { + self::Unset($sKey); + } + } + /** * @param string|array $key key to access to the session variable. To access to $_SESSION['a']['b'] $key must be ['a', 'b'] * @param $default