[eluser]Isos[/eluser]
Hi,
I am facing a strange and big problem.
I have an application with many roles (groups), one role have lots of users from all around the world, and around 900 from Kenya. I received lots of reports from the Kenyans in particular that when they login they would find different information that belong to many different people. So one might login and find another person's info, he logs out and logs in again and find another one different from the previous!
I am really confused. The application works so well with other roles which utilize common scripts in an extended class that validates sessions and everything! I even created a cookie to force more validation that when a user logs in and his username and password are validated his userid that is fetched from the db is registered in a cookie as well as in the session. So in every page there will be a validation to check if the userid in the session is the same as in the cookie, otherwise the session would be destroyed to force logout!
I thought this could be because of the session ID being tackeled through the same ISP that users maybe using or a certain IP or something. I am not that expert in protocols and how these things behave, but I am more confident it's a bug in the CI session library and related to the table!
Please advice, what could this be?
Thanks.