ClearFoundation Tracker - ClearOS
View Issue Details
0002209ClearOSapp-base - Base Systempublic2015-02-20 07:152015-08-13 08:29
dloper 
 
lowtrivialalways
closedfixed 
6.6.0 
6.7.0 Beta 1 
0002209: Improper redirect in app-base session.php
Non-root admins are redirected to an improper 'you cannot view this page' due to an invalid redirect.
file is contained in app-base
--- /usr/clearos/apps/base/controllers/session.php 2015-02-03 10:09:04.000000000 -0500
+++ /root/support/.common/normal/usr/clearos/apps/base/controllers/session.php 2014-09-05 13:07:10.226334795 -0400
@@ -236,7 +236,7 @@
                         $username = $this->input->post('clearos_username');
                         $valid_pages = $this->access_control->get_valid_pages($username);
                         if (preg_match('/^\/base\//', $post_redirect)
- && (in_array('dashboard', $valid_pages) || ($username === 'root'))
+ && (in_array('/app/dashboard', $valid_pages) || ($username === 'root'))
                             && clearos_app_installed('dashboard')
                         ) {
                             redirect('/dashboard');
No tags attached.
Issue History
2015-02-20 07:15dloperNew Issue
2015-02-23 20:12user2Statusnew => confirmed
2015-02-24 13:55user2Note Added: 0001377
2015-05-20 18:24user2Target Version6.6.0 Updates => 6.7.0 Beta 1
2015-08-10 17:27user2Categoryapp-dashboard - Dashboard => app-base - Base System
2015-08-12 14:17user2Statusconfirmed => resolved
2015-08-12 14:17user2Resolutionopen => fixed
2015-08-12 14:17user2Assigned To => user2
2015-08-13 08:29user2Statusresolved => closed
2015-08-13 08:29user2Assigned Touser2 =>

Notes
(0001377)
user2   
2015-02-24 13:55   
This was resolved in ClearOS 7, but it should be backported.