Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-22312

REST API v2 allows login for unactivated users

    XMLWordPrintable

Details

    Description

      When a user registers (doesn't matter which way) for a site but the account is not enabled (is_enabled setting in user_account is false) it's still possible to create a session for that user via eZ Publish REST Api v2's create session webservice.

      When then trying to read restricted content or perform any other action using this session the access is denied, still it shouldn't be possible to create a session at all.

      Attachments

        Activity

          People

            Unassigned Unassigned
            reneh reneh
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated: