Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unable to login using social login keys #4166

Closed
justinlusg opened this issue Oct 13, 2015 · 8 comments
Closed

Unable to login using social login keys #4166

justinlusg opened this issue Oct 13, 2015 · 8 comments

Comments

@justinlusg
Copy link

I've successfully saved the social login keys for Facebook. However, everytime when I try to login this page will always appear after facebook Authentication. Everytime I login with the same facebook account, system will always prompt me for my email, and first name and last name.

image

Possible security flaw:
I can fill in any email addresses in the system after i login with my Facebook account by entering the email address of the user in the email field.

@anandpdoshi
Copy link
Contributor

@justinlusg thanks for reporting this

@anandpdoshi
Copy link
Contributor

@justinlusg are you using the latest version? I am unable to reproduce this error in my local. Could also be due to some missing info from your profile or you might have denied permissions.

@justinlusg
Copy link
Author

@anandpdoshi yes, it is the latest version.. you can try it over here..

http://erpdemo.agtech.com.sg
Username: administrator
Password: demo

I've setup a demo site and tested it and it has the same problem.

The "One Last Step" will always appear no matter how many times I've login using Facebook, and during the "One Last Step", I am able to fill up any email address and gain access to that user (security flaw).

@fderyckel
Copy link
Contributor

Same thing for me.
It is just with Facebook login. It works fine with Google.

@fderyckel
Copy link
Contributor

For some reason, I can see that user/customer created by a Google Login works fine

screen shot 2015-10-21 at 07 23 42

But it stays blank with Facebook.

screen shot 2015-10-21 at 07 23 32

@justinlusg
Copy link
Author

@fderyckel I've not tried personally with Google, will try it.

@anandpdoshi might be a possible security flaw, which is critical to be resolve soon.

@justinlusg
Copy link
Author

After the latest update, it third party authentication disappeared under the user account. The Facebook authentication still does not work as well. The security flaw however is still there, I can use Facebook to authenticate and get into anybody's account without their permission/password.

@anandpdoshi
Copy link
Contributor

@justinlusg fixed. Facebook had changed its api

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants