#179 - Output before header() gives visitors admin rights

Description

If you have error reporting with notice in apache, will header()-redirect fail to work because there is some notice errors before header().

Scenario: You are not logged in, then going to the admincp - the header() will now try to redirect you to login, but fails because of the notice errors. The rest of the page will now render like you where logged in and show you some info like users and some settings, and you can create users/projects/milestones etc(!), (havent looked so much at it).

Activity

Jack closed as Invalid 15 years and 5 months ago

I've not been able to reproduce this, did you maybe setup the config.php file wrong?.

1 year and 5 months ago by Jack

  • Status Invalid Closed

Status

Closed
-
High

Details

Defect
2.0
Core
0.4
Critical

Tracking

Einar
15 years and 5 months ago
1 year and 5 months ago
0
-
-