This repository has been archived by the owner on Jul 8, 2022. It is now read-only.
Virtual Y + Y-USA Auth: Staff roles with emails in NWM gain access without password on normal landing page login #140
Labels
Type: Bug
Something isn't working
Repro Steps
Using the production North Penn Virtual Y site, which authorizes members using Y-USA Authentication:
Expected Behavior
Despite the email address for this user being in Nationwide Membership, a check needs to be made in the Virtual Y backend that checks for Admin-level roles assigned prior to signing that user in without having provided a password. They must login at the https://{sitename.y.org}/user/login page.
Actual Behavior
Admin-level users are able to gain access to the Virtual Y site without having to provide a password, if the email used is registered within Nationwide Membership.
Acceptance Criteria
Virtual Y users with either Site Owner or Virtual YMCA Editor roles should only be allowed to gain access to the Virtual Y site using the login prompt at https://{sitename.y.org}/user/login, even if the email address for the user is registered within Nationwide Membership.
The text was updated successfully, but these errors were encountered: