Logging in with no access

Radi A.'s Avatar

Radi A.

28 Apr, 2015 05:23 PM

very low priority....

When you have LDAP configured and an LDAP user logs in with no access, there is no appropriate error message. The login form just refreshes. This confuses my test user base - they don't know if they failed to log in or if something happened.

  1. Support Staff 1 Posted by Anton Gogolev on 28 Apr, 2015 06:57 PM

    Anton Gogolev's Avatar

    Radi, right?

    This is a known "issue" that is somewhat related to HgLab responding with HTTP 404 when it should be responding with HTTP 403. To prevent information disclosure, HgLab does not tell a user that "there is indeed a project named "X", but you don't have access to it", nor does it give hints as to whether one has been granted sign in permissions.

    This is not very intuitive and I think this will be changing in future versions.

  2. 2 Posted by Radi A. on 17 May, 2015 06:50 AM

    Radi A.'s Avatar

    Hi Anton,

    from what I have seen of the product, I feel that it should open the dashboard and say that you have no projects, no access to create projects or something similar.

    We have similar challenges in our own products with Windows Auth, I believe we handled this by giving a fake sub-status code, like "403.28" to prevent the ASP.NET MVC error handling. Unfortunately, I don't remember the details, but can check if needed.

    Regards,
    Radi A.

Reply to this discussion

Internal reply

Formatting help / Preview (switch to plain text) No formatting (switch to Markdown)

Attaching KB article:

»

Attached Files

You can attach files up to 10MB

If you don't have an account yet, we need to confirm you're human and not a machine trying to post spam.

Keyboard shortcuts

Generic

? Show this help
ESC Blurs the current field

Comment Form

r Focus the comment reply box
^ + ↩ Submit the comment

You can use Command ⌘ instead of Control ^ on Mac

Recent Discussions

12 Jan, 2023 12:25 PM
10 Jan, 2023 04:49 PM
03 Aug, 2022 01:49 PM
05 Jul, 2022 07:01 PM
28 Mar, 2022 04:42 PM

 

21 Jan, 2022 10:43 AM
20 Jan, 2022 10:45 AM
18 Jan, 2022 10:15 AM
19 Mar, 2021 06:13 PM
01 Mar, 2021 02:51 PM
01 Jan, 2021 02:19 AM