Make WordPress Core

Opened 16 years ago

Closed 10 years ago

#6978 closed defect (bug) (worksforme)

Accessing password protected posts though bloglines sends reader directly to dashboard

Reported by: midosibira's profile MidoSibira Owned by:
Milestone: Priority: normal
Severity: normal Version: 2.5.1
Component: Template Keywords: reporter-feedback
Focuses: Cc:

Description

Accessing password protected posts though bloglines sends non-admin reader directly to admin dashboard:

1) User selects a feed in bloglines
2) In the bloglines frame the user enters the password for the protected post
3) Wordpress dashboard is loaded in the bloglines frame instead of the protected post

This gives the non-admin user full access to the wordpress blog.

Attachments (2)

1_BloglinesPassword.jpg (123.4 KB) - added by MidoSibira 16 years ago.
Picture of wordpress protected post password prompt in bloglines
2_BloglinesDashboard.jpg (134.9 KB) - added by MidoSibira 16 years ago.
Picture of wordpress dashboard in bloglines

Download all attachments as: .zip

Change History (8)

@MidoSibira
16 years ago

Picture of wordpress protected post password prompt in bloglines

@MidoSibira
16 years ago

Picture of wordpress dashboard in bloglines

#1 @mrmist
16 years ago

  • Severity changed from major to normal

This isn't actually a security issue. The redirection only shows the dashboard if you're already logged in with a cookie. If you're not logged in, you get the login prompt.

It is, however, broken, because you should see the entry, not the dashboard/admin login box.

Still broke as of 2.6.1 beta2

#2 @ryan
15 years ago

  • Milestone changed from 2.7 to 2.9

#3 @Denis-de-Bernardy
15 years ago

  • Component changed from General to Template

#4 @ryan
14 years ago

  • Milestone changed from 2.9 to Future Release

#5 @iseulde
11 years ago

  • Keywords reporter-feedback added; Protected Post Bloglines removed

Is this still an issue?

#6 @nacin
10 years ago

  • Milestone Future Release deleted
  • Resolution set to worksforme
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.