Angela Schreiber created OAK-10466:
--------------------------------------

             Summary: Prevent anonymous user from being disabled
                 Key: OAK-10466
                 URL: https://issues.apache.org/jira/browse/OAK-10466
             Project: Jackrabbit Oak
          Issue Type: Wish
          Components: core, security
            Reporter: Angela Schreiber


today all users except the admin can be disabled preventing it from login. 
however, this is not sensible for the anonymous user. if anonymous access 
should not be possible it is recommended to use the corresponding configuration 
option that doesn't install the anonymous user in the first place.

for full backwards compatibility we should have consider placing this behind a 
configuration option such that consumers can opt out (and still disable the 
anonymous) if they really want.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to