User is redirected to the 404 page instead of the login page when the session expires.

Issue

  • The user is not prompted for login but to a 404 page when navigating in pages with restricted access if the user session expires or, if the user is not logged in and tries to access directly the url. 

Environment

  • DXP 7.4

Resolution

  • We disable this feature, that is present in former versions of DXP, to avoid the potential risks of the user enumeration and page enumeration attack vector.
  • When the Login Prompt is enabled, an attacker can guess users or private/restricted pages simply by the different responses the portal gives when accessing existing vs non-existing pages.
  • This behaviour can be reverted from Control Panel -> System Settings ->Login ->Login Prompt Enabled.

 

 

 

¿Fue útil este artículo?
Usuarios a los que les pareció útil: 1 de 1