Uploaded image for project: 'Hippo CMS'
  1. Hippo CMS
  2. CMS-14233

Log the 'login successful' event after authorization

    XMLWordPrintable

Details

    • Improvement
    • Status: Closed
    • Normal
    • Resolution: Fixed
    • 14.3.3
    • 14.5.0
    • cms
    • Flagged

    Description

      If some user tries to log into the CMS, authenticates correctly but is not authorized, there is still a 'login successful' event which is visible for other users in the activity stream.

      We could mitigate this by logging the 'login successful' event after authorization and also maybe renaming the current event (and not showing it in the activity stream).
       
      See org.hippoecm.frontend.session.PluginUserSession#login() which calls #checkApplicationPermission and org.hippoecm.frontend.model.JcrSessionModel#load and #flush

       

      Attachments

        Activity

          People

            clientserviceteam Client Service Team
            jhoffman Jeroen Hoffman
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: