TOLOGIX - ISLG App Rebuild

HIGH PRIORITY - Problem with IP Access in app.islg

Assigned to
Harsh Parikh, Tech Lead at DevIT Harsh P.
Notes
Further to the video below, we have a high priority issue that needs to be resolved within app.islg. We have had multiple reports from users indicating that they were getting access to George Mason University account, which has an IP address range accessible between 10.0.0.1 and 10.255.255.254:
When examining the usage details for George Mason University, between 2:24am and 8:43am EST, there was a sudden spike in Auto-IP usage on the account all coming through the same IP address: 10.68.138.10
This appears to be all auto-IP usage across the all subscribers during that period. Meaning every user (across all accounts) accessing the system via Auto-IP was getting their usage registered as originating 10.68.138.10 even though that is not IP address where the user was located when they accessed the system.

I assume that this issue is related to the deployment to app.islg that was occurring around this time, and the issue appeared to be resolved by 8:43am EST, but I'm very concerned that this happened. 

Harsh Parikh, Tech Lead at DevIT Harsh , can you please investigate the issue as a high priority and report back what happened and confirm whether the issue is now resolved. Also, I'm very concerned that this happened at all, and we need to examine how we're making deployments to app.islg going forward.

In the interim, we have disabled access to the 10.0.0.1 - 10.255.255.254 range, but we want to ensure we restore access as soon as possible so that we're not restricting access to users from the George Mason University's account.

Comments & Events

Harsh Parikh, Tech Lead at DevIT
Hi Morgan Maguire, CEO Morgan ,

I know this bug is due to last deployment. Actually, For deployment time we need to change one setting for IP address on server which we forgot yesterday so subscriber are auto-login within server IP (10.68.138.10).
We have resolved this issue by yesterday.

so, I can say that it was deployment mistake by yesterday. But, Don't worry, Yesterday we make one global setting so it will not happen again while we deploy new version.
Morgan Maguire, CEO
Morgan Maguire completed this to-do.