9 Replies Latest reply on Dec 13, 2011 4:14 PM by gebuh

    Bug in Seam or Internet Explorer security hole?

    cash1981

      Our test developer found something quite strange.
      We have a page, which is restricted with a admin role.


      This is what he did to find the error:



      1. Login as admin

      2. click on some of the admin stuff (creating users, listing users etc)

      3. Copy url of the admin page

      4. Logout

      5. Login as user

      6. Paste url of admin page



      Now in opera and firefox under Linux this didnt work. You got the error page with limited restriction.


      However on windows and Internet Explorer 7, when pasting the url, you can view ALL the admin pages through the url. Listing the users, creating users, the home page of the admin etc.


      Now is this a bug in Seam or is the security in Internet Explorer fu..ked??