Opened 10 years ago

Closed 10 years ago

Last modified 10 years ago

#3087 closed enhancement (wontfix)

[patch] users which are not staff try login into admin - provide better error message

Reported by: John D'Agostino <john.dagostino@…> Owned by: Adrian Holovaty
Component: contrib.admin Version:
Severity: minor Keywords: admin
Cc: Triage Stage: Unreviewed
Has patch: yes Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: UI/UX:

Description

currently if a user tries to login to the admin site and they aren't is_staff they are prompted with the standard error "Please enter a correct username and password." this patch instead prompts them with the message that they don't have the permission to access the site.

we use this on our site, because wondering users have "stumbled" upon the admin log in.

Attachments (1)

patch.diff (716 bytes) - added by John D'Agostino <john.dagostino@…> 10 years ago.

Download all attachments as: .zip

Change History (4)

Changed 10 years ago by John D'Agostino <john.dagostino@…>

Attachment: patch.diff added

comment:1 Changed 10 years ago by John D'Agostino <john.dagostino@…>

Summary: users which are not staff try login into admin - provide better error message[patch] users which are not staff try login into admin - provide better error message

comment:2 Changed 10 years ago by Adrian Holovaty

Resolution: wontfix
Status: newclosed

It's intentional that the error message is the same for both cases. It's a bit of security by obscurity.

comment:3 Changed 10 years ago by John D'Agostino <john.dagostino@…>

thought as such. Thanks Adrian

Note: See TracTickets for help on using tickets.
Back to Top