Page 1 of 1

Disable User Registration

PostPosted: July 18th, 2010, 2:54 am
by Brian Hatano
I have open registration disabled, but if I go directly to the wp registration page, it allows anyone to register and have full access.

I have page and post access set to "all" for Level 1, so I'm not sure why this is happening. This seems like a basic problem that I probably caused, but any ideas on why the security breach?

Thanks for the help!

Re: Disable User Registration

PostPosted: July 18th, 2010, 3:11 am
by Jason Caldwell
Hi Brian. Thanks for the report.

Make sure that you're not logged in as an Administrator during your testing. Administrators will always have the ability to register. s2Member does this purposely. Once you're logged out, you can re-test and registration should be disabled. If that does not work, clear your cache and delete browser cookies.

Also, check: s2Member -> General Options -> Open Registration. That needs to be Off.

Re: Disable User Registration

PostPosted: July 18th, 2010, 5:35 am
by Brian Hatano
Thanks for the quick reply, Jason!

I made sure I was logged out and Open Registration was not allowed before testing the first time, but maybe the cache or cookies were causing me to be given access to registration...

It's working properly now, though. Any ideas on why I was given access to a registration page the first time? Hopefully not repeatable by a hacker, I presume...

Re: Disable User Registration

PostPosted: July 22nd, 2010, 6:02 am
by Jason Caldwell
Thanks for reporting back Brian.
I can only assume it had something to do with cookie authentication, a browser cache, or you were logged in as an Administrator. If you experience this again, and you cannot attribute the problem to one of the circumstances that I've mentioned here; please report back so we can re-open this ticket.