Private archive specific message URL lost in authorization

Bug #266164 reported by Mark Sapiro
2
Affects Status Importance Assigned to Milestone
GNU Mailman
Fix Released
Low
Mark Sapiro

Bug Description

If a user without an authorization cookie goes to a URL
such as

http://www.example.com/mailman/private/list-name/yyyy-Month/nnnnnn.html

the user will get the private archives authorization
page and after filling in e-mail address and password
and clicking Let me in... will be taken to the main
index for the list at

http://www.example.com/mailman/private/list-name/

instead of to the original URL.

[http://sourceforge.net/tracker/index.php?func=detail&aid=1080943&group_id=103&atid=100103]

Tags: web-cgi

Related branches

Revision history for this message
Pabs3-users (pabs3-users) wrote :

There is a fix for this issue in a debian bug report:
http://bugs.debian.org/298842

Revision history for this message
Mark Sapiro (msapiro) wrote :

Fixed in 2.1.7.

Revision history for this message
Mark Sapiro (msapiro) wrote :

The original fix released in Mailman 2.1.7 was incomplete. It didn't properly account for http://www.example.com/mailman/private/list-name.mbox/listname.mbox URLs. This oversight has been corrected and committed on the 2.1 branch at rev 1217.

Changed in mailman:
assignee: nobody → Mark Sapiro (msapiro)
importance: Medium → Low
status: Fix Released → Fix Committed
Mark Sapiro (msapiro)
Changed in mailman:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.