-
Incident report
-
Resolution: Unresolved
-
Trivial
-
7.0.7rc1, 7.2.0rc1 (master)
-
None
-
None
Steps to reproduce:
- Navigate to log-in page
- Change URL to: zabbix.php?action=export.hosts&backurl=javascript:alert(1) and navigate there.
- User is redirected to ''you are not logged in page''.
- Press login.
- Add username and password and try to sign in.
Result:
Result: user remains on log-in page while something is downloading in the background.
Each time user tries to sign in, there is a new attempt to download the file and user is not redirected anywhere.
From a UI perspective, it would be better to display, for example, no access to page error, where user can press "Go to dashboards" button after logging in (expected result must be discussed with PO).
Note: reproducible in 7.0 and master branches.
Issue moved from DEV-4084 sub-issue (2).