← Back to team overview

mahara-contributors team mailing list archive

[Bug 1777785] [NEW] Users from a suspended institution can still log in

 

Public bug reported:

It should not be possible for people to log into their account if their
institution has been suspended. the latest fix for that also for
external auth methods is https://reviews.mahara.org/#/c/6671/

This did not work on a Mahara 17.04 for SAML auth and on a Mahara
18.10dev for internal auth.

To replicate:

1. Have an institution with one member and a site admin.
2. Site admin suspends the institution.
3. Expected result: Institution member cannot log in anymore.
   Actual result: Institution member can still log in.

This would need to be tested with all auth methods: internal, LDAP,
SAML, MNet, LTI

** Affects: mahara
     Importance: High
         Status: Confirmed

** Affects: mahara/17.04
     Importance: High
         Status: Confirmed

** Affects: mahara/17.10
     Importance: High
         Status: Confirmed

** Affects: mahara/18.04
     Importance: High
         Status: Confirmed

** Affects: mahara/18.10
     Importance: High
         Status: Confirmed


** Tags: regression

** Also affects: mahara/17.04
   Importance: Undecided
       Status: New

** Also affects: mahara/17.10
   Importance: Undecided
       Status: New

** Also affects: mahara/18.10
   Importance: High
       Status: Confirmed

** Also affects: mahara/18.04
   Importance: Undecided
       Status: New

** Changed in: mahara/17.04
       Status: New => Confirmed

** Changed in: mahara/17.10
       Status: New => Confirmed

** Changed in: mahara/18.04
       Status: New => Confirmed

** Changed in: mahara/17.04
   Importance: Undecided => High

** Changed in: mahara/17.10
   Importance: Undecided => High

** Changed in: mahara/18.04
   Importance: Undecided => High

** Changed in: mahara/17.04
    Milestone: None => 17.04.10

** Changed in: mahara/17.10
    Milestone: None => 17.10.7

** Changed in: mahara/18.04
    Milestone: None => 18.04.3

** Changed in: mahara/18.10
    Milestone: None => 18.10.0

-- 
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask on #mahara-dev or mahara.org forum before editing or unsubscribing it!
https://bugs.launchpad.net/bugs/1777785

Title:
  Users from a suspended institution can still log in

Status in Mahara:
  Confirmed
Status in Mahara 17.04 series:
  Confirmed
Status in Mahara 17.10 series:
  Confirmed
Status in Mahara 18.04 series:
  Confirmed
Status in Mahara 18.10 series:
  Confirmed

Bug description:
  It should not be possible for people to log into their account if
  their institution has been suspended. the latest fix for that also for
  external auth methods is https://reviews.mahara.org/#/c/6671/

  This did not work on a Mahara 17.04 for SAML auth and on a Mahara
  18.10dev for internal auth.

  To replicate:

  1. Have an institution with one member and a site admin.
  2. Site admin suspends the institution.
  3. Expected result: Institution member cannot log in anymore.
     Actual result: Institution member can still log in.

  This would need to be tested with all auth methods: internal, LDAP,
  SAML, MNet, LTI

To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1777785/+subscriptions


Follow ups