globaleaks / globaleaks-whistleblowing-software

GlobaLeaks is free, open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.
https://www.globaleaks.org
Other
1.23k stars 269 forks source link

User can not be authenticated #4098

Closed elbill closed 4 months ago

elbill commented 4 months ago

What version of GlobaLeaks are you using?

4.15.5

What browser(s) are you seeing the problem on?

Chrome, Microsoft Edge, All

What operating system(s) are you seeing the problem on?

Windows

Describe the issue

For a specific tenant test user I get the message authentication failed. I send a reset link I change password and enter the platform. I even use the password to access access code successfuly. When log out and try to log in I get the same message. No error codes seem to be generated. I have created a user in the same tenat and it behaves ok. Same with other tenats. However I do not feel secure that this is not going to happen again to other users. I had a user complaining for something similar (however they told me the managed to set a password successfuly eventualy). In may case I was not able to logi in properly

Proposed solution

When password is correct users should be able to log in.

evilaliv3 commented 4 months ago

Thank you @elbill

Are you sure to be logging in with the correct username?

In my opinion the reset works since you use the email to ask for the reset but then you fail a second access because you do not use the correct username.

Send me privately a screenshot of the full user configuration. As well please check if this user has a special role that corresponds to some ip or network block defined in your network settings

elbill commented 4 months ago

You were correct. Messed up user name with name... thanks