[Tickets #1320] NEW: _horde_hook_postauthenticate does not work correctly when IMP is used for authentication

bugs at bugs.horde.org bugs at bugs.horde.org
Mon Feb 7 09:19:16 PST 2005


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/?id=1320
-----------------------------------------------------------------------
 Ticket     | 1320
 Created By | luc.germain at USherbrooke.ca
 Summary    | _horde_hook_postauthenticate does not work correctly when IMP is used for authentication
 Queue      | Horde Base
 Version    | 3.0.2
 State      | Unconfirmed
 Priority   | 3. High
 Type       | Bug
 Owners     | 
-----------------------------------------------------------------------


luc.germain at USherbrooke.ca (2005-02-07 09:19) wrote:

On Horde 3.0.2, I defined the hook function _horde_hook_postauthenticate to
limit the users who have access to horde, and activated it's use in the
horde configuration. The authentication is done by IMP through  IMAP, and
the hook  is used to further restrict access to a list of users.

For users not in the list, the login page does indeed show that the login
failed, but the menu in the left  frame still appear complete as if the user
was authenticated, and the user can access to all others apps except his
mailbox through the menu. I think this function should block access to all
applications.




More information about the bugs mailing list