Uploaded image for project: 'Blesta Core'
  1. Blesta Core
  2. CORE-1780

User login logs should indicate a failure when logging into the wrong company

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 4.0.0-b1
    • Component/s: None
    • Labels:
      None

      Description

      When a user logs into the wrong company with successful login credentials, a success log is added to the `log_users` table. However, since they logged into the wrong company, the login was a failure. The result status should indicate this failure in the log.

      This issue primarily affects staff appearing in the System Overview plugin when they login to the wrong company.

        Activity

        Hide
        tyson Tyson Phillips (Inactive) added a comment -

        Successful logins to the wrong company are handled during post auth by the login controllers.

        We should consider updating the login rules to cause an error regarding the invalid company if the user is a client/staff and do not belong to the company.

        Show
        tyson Tyson Phillips (Inactive) added a comment - Successful logins to the wrong company are handled during post auth by the login controllers. We should consider updating the login rules to cause an error regarding the invalid company if the user is a client/staff and do not belong to the company.

          People

          • Assignee:
            jonathan Jonathan Reissmueller
            Reporter:
            tyson Tyson Phillips (Inactive)
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:
              Fix Release Date:
              15/Sep/16