# Panel keep login out

**URL:** <https://forum.getkirby.com/t/panel-keep-login-out/6587>\
**Category:** Questions\
**Tags:** v2\
**Created:** [February 10, 2017, 1:00pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587 "2017-02-10T13:00:50Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![scandella](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@scandella](https://forum.getkirby.com/u/scandella)\
**Post date:** [February 10, 2017, 1:00pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/1 "2017-02-10T13:00:50Z")

</div>

Hi,  
Using Kirby 2.4.1, my users are log out from the panel in various random circumstances. It could happen when saving a page or when going back to the dashboard, sometimes even at login.  
When that happened, the dev console briefly show a:  
`SyntaxError: Unexpected token <`

[I’ve seem a topic about it](https://forum.getkirby.com/t/panel-keeps-logging-me-out/2747), but I did not get what the solution was, except editing some files in the Kirby core, which is clearly not a solution.

Thanks for your help

---

<div class="post-metadata">

**Author:** ![gillesvauvarin](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/gillesvauvarin/32/2351_2.png) [@gillesvauvarin](https://forum.getkirby.com/u/gillesvauvarin)\
**Post date:** [February 10, 2017, 1:18pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/2 "2017-02-10T13:18:11Z")

</div>

Just to say that I have similar issues on my local dev install.

Linux Ubuntu  
Caddy Server + php7

I’m going to test on VPS with some different web server environments (Apache + nginx reverse proxy and nginx allone) and will tell you if random logout append.

---

<div class="post-metadata">

**Author:** ![leester](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/leester/32/8738_2.png) [@leester](https://forum.getkirby.com/u/leester)\
**Post date:** [February 10, 2017, 4:10pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/3 "2017-02-10T16:10:31Z")

</div>

Same here. I can login but after I click on any link, it logs me out back to the panel login page. I have made no changes to any files. I have even re-uploaded the PANEL and KIRBY folders with no success.

I have removed all plugins to see if there were any issues here but nothing.

I have even checked all with htaaccess to see if any issues there but can’t find any.

---

<div class="post-metadata">

**Author:** ![texnixe](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/texnixe/32/5754_2.png) [@texnixe](https://forum.getkirby.com/u/texnixe)\
**Post date:** [February 10, 2017, 4:15pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/4 "2017-02-10T16:15:13Z")

</div>

Have you tried to use a custom session fingerprint like suggested in that post quoted above:

```auto
<?php

s::$fingerprint = function() {
  return 'some fingerprint';
};

```

---

<div class="post-metadata">

**Author:** ![scandella](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@scandella](https://forum.getkirby.com/u/scandella)\
**Post date:** [February 10, 2017, 4:29pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/5 "2017-02-10T16:29:05Z")

</div>

I’ve done a quick test and it seem this function solve the panel logout.  
Can you elaborate about what this function is about and when to use it or not?  
I’m not familiar with “fingerprint” session.

---

<div class="post-metadata">

**Author:** ![texnixe](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/texnixe/32/5754_2.png) [@texnixe](https://forum.getkirby.com/u/texnixe)\
**Post date:** [February 10, 2017, 4:36pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/6 "2017-02-10T16:36:02Z")

</div>

I think the purpose of the session fingerprint is to identify the session and is thus a security feature. But it seems that the Kirby fingerprint, which is IP or user agent based, can cause issues in some environments, where those parameters might change.

---

<div class="post-metadata">

**Author:** ![scandella](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@scandella](https://forum.getkirby.com/u/scandella)\
**Post date:** [February 10, 2017, 4:46pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/7 "2017-02-10T16:46:53Z")

</div>

Thanks.  
I wonder if the problem is solved for the two users above too.

---

<div class="post-metadata">

**Author:** ![gillesvauvarin](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/gillesvauvarin/32/2351_2.png) [@gillesvauvarin](https://forum.getkirby.com/u/gillesvauvarin)\
**Post date:** [February 10, 2017, 6:22pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/8 "2017-02-10T18:22:15Z")

</div>

Sorry but I don’t know what is a custom session fingerprint?

How I’m suppose to use this piece of code? just copy/past it in the config file?  
Do I need to replace ‘some fingerprint’ by something else?

And do I need to get the code from the develop branch of the toolkit?

I would be grateful for some explanations 🙂

---

<div class="post-metadata">

**Author:** ![scandella](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@scandella](https://forum.getkirby.com/u/scandella)\
**Post date:** [February 10, 2017, 7:42pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/9 "2017-02-10T19:42:49Z")

</div>

Gilles,  
Personally, I’ve just pasted this function “as in” in the config file.  
I guess the 'some fingerprint" value in return is just a dummy one to return something, instead of a null value that caused the logout we’ve experienced.  
But I’m no expert there.

---

<div class="post-metadata">

**Author:** ![texnixe](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/texnixe/32/5754_2.png) [@texnixe](https://forum.getkirby.com/u/texnixe)\
**Post date:** [February 10, 2017, 7:50pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/10 "2017-02-10T19:50:34Z")

</div>

This is the fingerprint method:

```auto
public static function fingerprint() {

    // custom fingerprint callback
    if(is_callable(static::$fingerprint)) {
      return call(static::$fingerprint);
    } 

    if(!r::cli()) {
      return sha1(Visitor::ua() . (ip2long($_SERVER['REMOTE_ADDR']) & ip2long('255.255.0.0')));      
    } else {
      return '';
    }
  }

```

So, if no custom fingerprint is used, the fingerprint is created like this:

```auto
 return sha1(Visitor::ua() . (ip2long($_SERVER['REMOTE_ADDR']) & ip2long('255.255.0.0')));  

```

In your custom fingerprint, you can do whatever you want, return a string or return only parts of the above, e.g.

```auto
return sha1(Visitor::ua());

```

or whatever works for you.

---

<div class="post-metadata">

**Author:** ![gillesvauvarin](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/gillesvauvarin/32/2351_2.png) [@gillesvauvarin](https://forum.getkirby.com/u/gillesvauvarin)\
**Post date:** [February 10, 2017, 8:00pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/11 "2017-02-10T20:00:43Z")

</div>

Thank you both for your answer, I’m a little bit less ignorant now 😉

---

<div class="post-metadata">

**Author:** ![distantnative](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/distantnative/32/11319_2.png) [@distantnative](https://forum.getkirby.com/u/distantnative)\
**Post date:** [February 6, 2025, 4:52pm UTC](https://forum.getkirby.com/t/panel-keep-login-out/6587/12 "2025-02-06T16:52:44Z")

</div>


