WordPress.org

Make WordPress Core

Opened 14 years ago

Closed 8 years ago

#6978 closed defect (bug) (worksforme)

Accessing password protected posts though bloglines sends reader directly to dashboard

Reported by: MidoSibira Owned by:
Milestone: Priority: normal
Severity: normal Version: 2.5.1
Component: Template Keywords: reporter-feedback
Focuses: Cc:

Description

Accessing password protected posts though bloglines sends non-admin reader directly to admin dashboard:

1) User selects a feed in bloglines
2) In the bloglines frame the user enters the password for the protected post
3) Wordpress dashboard is loaded in the bloglines frame instead of the protected post

This gives the non-admin user full access to the wordpress blog.

Attachments (2)

1_BloglinesPassword.jpg (123.4 KB) - added by MidoSibira 14 years ago.
Picture of wordpress protected post password prompt in bloglines
2_BloglinesDashboard.jpg (134.9 KB) - added by MidoSibira 14 years ago.
Picture of wordpress dashboard in bloglines

Download all attachments as: .zip

Change History (8)

@MidoSibira
14 years ago

Picture of wordpress protected post password prompt in bloglines

@MidoSibira
14 years ago

Picture of wordpress dashboard in bloglines

#1 @mrmist
13 years ago

  • Severity changed from major to normal

This isn't actually a security issue. The redirection only shows the dashboard if you're already logged in with a cookie. If you're not logged in, you get the login prompt.

It is, however, broken, because you should see the entry, not the dashboard/admin login box.

Still broke as of 2.6.1 beta2

#2 @ryan
13 years ago

  • Milestone changed from 2.7 to 2.9

#3 @Denis-de-Bernardy
13 years ago

  • Component changed from General to Template

#4 @ryan
12 years ago

  • Milestone changed from 2.9 to Future Release

#5 @iseulde
8 years ago

  • Keywords reporter-feedback added; Protected Post Bloglines removed

Is this still an issue?

#6 @nacin
8 years ago

  • Milestone Future Release deleted
  • Resolution set to worksforme
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.