Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-17941

(eZ comments) activating a comment subscription gives access to a "Go to settings" button that, when pressed, raises an "Access denied" for anonymous users

    XMLWordPrintable

Details

    Description

      Hi,
      when an anonymous users confirm a comments subscription, he is redirected to a "The subscription is activated! " page. in that same page, there is a button "Go to settings" that, when pressed, raises the information:
      "Access denied

      You do not have permission to access this area.

      Possible reasons for this are:

      • You are currently not logged in to the site, to get proper access create a new user or login with an existing user.
      • You misspelled some parts of your URL, try changing it.
        "

      Should this button exist?

      Steps to reproduce
      Setup - Give anonymous user access to post comments
      
         1. Log in as admin in ezwebin admin
         2. Click on "User accounts" in top menu
         3. Click "Roles and policy" in left menu
         4. Click edit icon next to "Anonymous"
         5. Click "New policy" button
            Module: comment
            Function: Add
         6. Click "Grant full access"
         7. Click "New policy" button
            Module: comment
            Function: Read
         8. Click "Grant full access"
         9. Click "New policy" button
            Module: comment
            Function: Activate
        10. Click "Grant full access"
        11. Click "Save" button
      
        Create  a "News" folder
        Click on the link to access the news folder
        Create an article with comments named "Comment system testing"
       
      Post an anonymous comment
      
         1. Go to webin as anonymous
         2. Click "News" in top menu
         3. Go to plain site (don't login)
         4. Click on the "Comment system testing" article in the sub items list
         5. Fill in the comment form as follows:
            Title: Comment by an anonymous user
            Name: Anonymous name
            Website: leave blank
            Email: [ an email address the tester has access to ]
            Content: This is an anonymous comment
            Notification: check
         6. Click on "Add comment"
      
      Check that an email confirmation is required
      
         1. Validate that an email explaining that an email confirmation is required is sent to the email address provided above.
         2. Click on the confirmation link on the email
         3. Verify that the user is directed to a page informing him that the activation was done
         4. Click on the "Go to settings" button
         
         <here the deny access appears>
      

      Attachments

        Activity

          People

            chen chen
            pcardiga pcardiga
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: