Skip to:
Content
Pages
Categories
Search
Top
Bottom

User automatically logged in on register


  • satus
    Participant

    @satus

    Hi,

    When a new user registers using the standard Buddypress user form, they receive the activation email and that all works great! However, they are automatically logged in to the site when they click complete on the register form and can continue to use the site as a standard user. If they are to log out, they cannot get back in. But we recently had someone spam our site with logins and comments and votes using this exploit.

    Any ideas on where to look to solve this? Essentially, i don’t want the register form to automatically log the user in..

    Any help you be much appreciated. Thank you.

Viewing 5 replies - 1 through 5 (of 5 total)

  • Venutius
    Moderator

    @venutius

    If you have not added user moderation then the user becomes active once they have activated and they are free to use your site how they like. They can log in, since activation is the last step of user authentication.


    satus
    Participant

    @satus

    @venutius Thanks for the fast response. I’m not sure i follow what you mean. The user cannot log in until they activate their account through their email address, so that is set up correctly (as far as i can tell), is this the user moderation you’re refering to, or is there something else i’ve missed? The issue is, they are automatically logged in as soon as they click to complete the register button. If they then log out of their account, they cannot get back in to the site without activating through the email link. It’s just the initial log in that is causing the problems.

    Thank you


    Venutius
    Moderator

    @venutius

    No, that’s not the behaviour, once they complete registration they are left logged out. If they try to log in it refuses to allow them until they have activated.


    satus
    Participant

    @satus

    @venutius Yes that’s what should happen. But that is not happening on my site. They are logged in once they complete registration.


    Venutius
    Moderator

    @venutius

    Seems like a strange one for a plugin conflict but that’s the starting point, deactivate all your plugins and switch to 2016 in order to establish a baseline. With that configuration it will work, then introduce the plugins one by one until you find the culprit.

Viewing 5 replies - 1 through 5 (of 5 total)
  • You must be logged in to reply to this topic.
Skip to toolbar