Issue Type: Bug Bug
Affects Versions: 2.3.1
Assignee: Unassigned
Components: config
Created: 22/Jul/14 10:30 AM
Description:

When you register, after double opt-in, you succesfully log in, but you are not able to see protected pages.

To replicate:
1) go to http://demopublic.magnolia-cms.com
2) register (http://demopublic.magnolia-cms.com/demo-project/members-area/registration.html)
3) click email link to activate your user
4) login

HERE you see the issue: you stay logged in (your name is prompted by PUR login form component, with LOGOUT button) but page "Protected" is not accessible.

The problem seems to be the roles assigned to the new user: anonymous + public-user-registration-base

  • role "anonymous" should be removed, since it contains a DENY rule (the one managed by security callback..)
  • role "public-user-registration-base" is already included in group "demo-project-members", so it is redundant.

In my tests removing both the roles fixed the login procedure.
M.

Environment: demopublic.magnolia-cms.com
Project: Magnolia Public User Registration
Priority: Critical Critical
Reporter: Matteo Pelucco
Original Estimate: 10m
Remaining Estimate: 10m
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira



----------------------------------------------------------------
For list details, see: http://www.magnolia-cms.com/community/mailing-lists.html
Alternatively, use our forums: http://forum.magnolia-cms.com/
To unsubscribe, E-mail to: <[email protected]>
----------------------------------------------------------------

Reply via email to