Admin and Registration Problems Admin and Registration Problems
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

Admin and Registration Problems

Started by porcelina, May 05, 2012, 11:47:59 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

porcelina

About a month ago, my website was hacked and I had to do a clean out of cpanel. Afterward, my host recovered my photo gallery and I've since upgraded to 1.5.20. I'm now encountering two problems:

1. Somehow my admin account was deleted, so I followed the instructions in coppermine documentation, using the admin password provided, etc. My account is now back up and it is recognizing that I'm the one who has uploaded all the photos to the gallery, but it is logging me in as a guest instead of showing the admin panel.

2. I've set access permissions for new users so that I have to receive an email whenever a new user registers, and approve their registration via the email link. The email bit still seems to be working fine in that I am notified whenever someone new registers. However, when I click on the link to activate their account, I get a message saying something to the effect of "Your registration has now been sent to the admin for approval."  I am assuming this is the same message the user receives before I actually approve them. I've been having to approve users manually, one at a time through the user panel in my gallery, which is extremely slow to load (however now I can't do this as it's not actually letting me log in as admin). Also, when I try and do this, often times I get an error message saying there is no valid form token.

Any idea how to fix either of these issues?

http://www.vivandlarry.com/gallery

Thanks

porcelina

Was able to fix issue no. 1--my account was set to the wrong group number in phpmyadmin.

Still having some issues with the registration and approval of new users, though. I tried setting up a test account, and it seems to be sending me two emails. The first says "A new user with the username "testing" has registered in your gallery" but the activation link takes a while to come through and is included in a separate email.

Αndré

What's your "email verification on registration" setting?

porcelina

I have the following settings checked:

User registration requires email verification: YES
Notify admin of user registration by email: YES
Admin activation of registrations: YES

It only activates new users when I click twice on the activation link that comes through with each email notification.

Αndré

Seems that you (as admin) get the activation email too soon. The intended procedure is as follows:
- User submits the registration form
- User receives email address verification email
(- I currently don't know if you (as admin) also receives an email that somebody registered in your gallery, but it seems that you also get that email address verification email)
- User visits the email address verification URL
- Gallery admin receives an activation email
- Gallery admin visits the activation URL
- User is activated and receives a confirmation email

Unfortunately the URL for the user and admin is the same, so if you visit the URL you verify the user's email address accidentally.


Can you please check the whole email correspondence during the registration process as user AND admin and post the complete email contents with timestamps and some information what you did as admin or user before the emails have been sent? That would help me a lot to debug the process. I'll try to check that later (tomorrow at the earliest), too.

porcelina

Sorry for the delayed response to this.

The first thing that happens is I receive two emails every time someone new registers in my gallery. Here is an example:

First email:
QuoteVivien Leigh & Laurence Olivier | Photo Gallery - Registration notification

A new user with the username "alexifera" has registered in your gallery

11:39 PM (9 hours ago)

Second email:
QuoteVivien Leigh & Laurence Olivier | Photo Gallery - Registration request

A new user with the username "alexifera" has registered in your gallery.
In order to activate the account, you need to click on the link below or copy and paste it in your web browser.

http://www.vivandlarry.com/gallery/register.php?activate=6be11503797f3c2681fdf2c975427621

11:40 PM (9 hours ago)

At which point I click on the activation link and it either says the account is now activated OR, as in most cases, that an email has been sent to the admin (me) for approval.

porcelina

Whenever I click on the activation link from my email inbox and it tells me that an email has been sent to the admin for approval, I never receive a new activation link in my inbox. I also then have to log in to my gallery and manually activate users (sometimes when this happens, it shows an error message and it says there is no valid form token).

Αndré

So you get the "second" email simultaneously with the "first" email, without any user interaction (i.e. email verification)? It will be helpful if you describe the process as detailed as possible.

porcelina

Yes, I get both emails more or less simultaneously. 9 times out of 10, I then have to log into my gallery and manually activate each user because when i click on the activation link that comes through to my email inbox, I get a message saying:

QuoteThank you.
Your request for account activation was sent to the admin. You will receive an email if approved.

It seems that I am getting the activation link that should be sent to the individual users when they register.

Αndré

Either you get them simultaneously or not. Please try to register a new user yourself and check if the above described registration process works as expected or not.

Directly after registration your new user get an email with the activation link. Additionally, the admin get an information email ("first email").

Now, please wait some minutes before you click the activation link as user to verify that the admin doesn't get an email with the activation link yet.