Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Signed-out user can access the bookmarks page when users are allowed to explore resources without signing in #9057

Closed
MisRob opened this issue Jan 28, 2022 · 0 comments · Fixed by #9142
Assignees
Labels
APP: Learn Re: Learn App (content, quizzes, lessons, etc.) bug Behavior is wrong or broken DEV: frontend P2 - normal Priority: Nice to have

Comments

@MisRob
Copy link
Member

MisRob commented Jan 28, 2022

Observed behavior

With this device settings:

device

I can access the bookmarks page as a signed-out user via URL /en/learn/#/bookmarks

bookmarks-page

Expected behavior

Even though users are allowed to explore resources without signing in, giving access to the bookmarks page still doesn't make sense for anonymous users. For signed-out users, it should rather show "You must be signed in" message:

message

User-facing consequences

Anonymous users can access pages that shouldn't be visible to them

Steps to reproduce

  1. Select "Allow users to explore resources without signing in" in device settings as an admin
  2. Sign out
  3. Type /en/learn/#/bookmarks URL to the browser address bar

Context

  • Kolibri version: Kolibri 0.15.1.dev0+git.20220127215827
  • Operating system: Ubuntu 20.04.3 LTS
  • Browser: Chrome Version 97.0.4692.99 (Official Build) (64-bit)
@MisRob MisRob added bug Behavior is wrong or broken P2 - normal Priority: Nice to have APP: Learn Re: Learn App (content, quizzes, lessons, etc.) DEV: frontend labels Jan 28, 2022
@sairina sairina self-assigned this Feb 26, 2022
@sairina sairina closed this as completed Mar 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
APP: Learn Re: Learn App (content, quizzes, lessons, etc.) bug Behavior is wrong or broken DEV: frontend P2 - normal Priority: Nice to have
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants