Details
-
Bug
-
Resolution: Unresolved
-
High
-
None
-
5.2, 5.3-dev, 5.3, 1.6.0
Description
When a user registers (doesn't matter which way) for a site but the account is not enabled (is_enabled setting in user_account is false) it's still possible to create a session for that user via eZ Publish REST Api v2's create session webservice.
When then trying to read restricted content or perform any other action using this session the access is denied, still it shouldn't be possible to create a session at all.
Attachments
Issue Links
- relates to
-
EZP-22220 Session creation in REST API doesn't use Symfony SecurityContext
- Closed