-
Bug
-
Resolution: Unresolved
-
Blocker
-
4.10.0
-
None
-
None
-
4.10 M8
-
Oui
Site application forward all MFA code request to the cms, but the admin population is handled by the site application resulting in requesting an code for an unexisting user
Step to reproduce :
- add a mail to a user in the admin population of the site
- remove a mail from the admin user of the cms
- try to connect to the admin of the site application for this user -> OUPS
Even worse, if a user with the same login exists in the admin population of the cms and this user has an email, he will receive a code, and the code is functionnal to authenticate the user in site !
- discovered while testing
-
RUNTIME-4334 The migration 'org.ametys.core.script.multifactorauthentication.SqlTablesInit' cannot be done in safe mode
-
- Available for review
-