Page MenuHomePhabricator

Edit tutorial persists after logging out
Closed, ResolvedPublic


Author: jgonera


  1. Go to a page and click the main edit button.
  2. Log in using the CTA link.
  3. Click cancel in the tutorial.
  4. Log out and click the "Return to page_name" link.
  5. You're back on the page, logged out and with the tutorial visible.

Version: unspecified
Severity: normal



Event Timeline

bzimport raised the priority of this task from to Low.Nov 22 2014, 2:13 AM
bzimport set Reference to bz53261.
bzimport added a subscriber: Unknown Object (MLST).

It will do since the login/logout urls pass all existing query string parameters. We probably want to whitelist the ones that we need...

jgonera wrote:

Or you can simply not run the whole tutorial code if the user is logged out.

Change 82764 had a related patch set uploaded by JGonera:
Don't show newbie tutorials after logging out

Change 82764 merged by jenkins-bot:
Don't show newbie tutorials after logging out