Warning: Can't synchronize with repository "(default)" (Unsupported version control system "svn": No module named svn). Look in the Trac log for more information.

Ticket #1212 (closed defect: fixed)

Opened 13 years ago

Last modified 12 years ago

Identity is not completing the logging out proccess correctly with SOProvider

Reported by: claudio.martinez Owned by: anonymous
Priority: high Milestone: 1.0
Component: Identity Version: trunk
Severity: major Keywords:
Cc:

Description

Browsing identity's code I found a bug that might have security consecuences.

On source:trunk/turbogears/identity/soprovider.py#2242 line 137 the "anon.anonymous= True" is triggering an exception since that property is read-only and the current identity is not being setted as anonymous correctly since there's a 'except: pass' on the whole method. Doubled edged sword that is.

Change History

comment:1 Changed 13 years ago by jorge.vargas

did you read #1211?

comment:2 Changed 13 years ago by alberto

  • Status changed from new to closed
  • Resolution set to fixed

Fixed in [2243]

Note: See TracTickets for help on using tickets.