![]() |
|
|
|
|
Issue Type:
|
Bug
|
|
Affects Versions:
|
2.3.1 |
|
Assignee:
|
Unassigned |
|
Components:
|
config |
|
Created:
|
22/Jul/14 10:30 AM
|
|
Description:
|
When you register, after double opt-in, you succesfully log in, but you are not able to see protected pages.
To replicate:
1) go to http://demopublic.magnolia-cms.com
2) register (http://demopublic.magnolia-cms.com/demo-project/members-area/registration.html)
3) click email link to activate your user
4) login
HERE you see the issue: you stay logged in (your name is prompted by PUR login form component, with LOGOUT button) but page "Protected" is not accessible.
The problem seems to be the roles assigned to the new user: anonymous + public-user-registration-base
- role "anonymous" should be removed, since it contains a DENY rule (the one managed by security callback..)
- role "public-user-registration-base" is already included in group "demo-project-members", so it is redundant.
In my tests removing both the roles fixed the login procedure.
M.
|
|
Environment:
|
demopublic.magnolia-cms.com
|
|
Project:
|
Magnolia Public User Registration
|
|
Priority:
|
Critical
|
|
Reporter:
|
Matteo Pelucco
|
|
Original Estimate:
|
10m
|
|
Remaining Estimate:
|
10m
|
|
|
|
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira
|
----------------------------------------------------------------
For list details, see: http://www.magnolia-cms.com/community/mailing-lists.html
Alternatively, use our forums: http://forum.magnolia-cms.com/
To unsubscribe, E-mail to: <
[email protected]>
----------------------------------------------------------------