Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-29061

test@liferay.com created by setupwizard even when different user specified

    Details

      Description

      Steps to reproduce:

      • unzip tomcat bundle
      • delete data directory, create new (empty) data directory
      • (create deploy directory for license in EE version)
      • start tomcat
      • enter a specific user in setupwizard (not test@liferay.com)
      • create default database (I used hsql, so no other configuration than usernames/mail)
      • Login and check users available: You'll find the user specified in setup-wizard as well as test@liferay.com, with the "usual" default password and administrative permissions.

      Workaround: remove/deactivate test@liferay.com after creation of the database

      Not a real security threat (thus I'll leave this ticket public despite the "security" categorization: Needs to be properly documented so that the default user will be deactivated - this is step one of this documentation.

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Days since last comment:
                  7 years, 11 weeks ago

                  Packages

                  Version Package
                  6.1.2 CE GA3
                  6.1.30 EE GA3
                  --Sprint 11/12
                  6.2.0 CE M2