Hi,

Logintoboggan offers the pre-auth role logic. However, *any* new role will always inherit the authenticated users' permissions. See screenshot attached. It is not possible to give the pre-auth role different permissions from the authenticated role. Try it yourself. Go to user user permissions and try to uncheck a 'pre-auth' role's permissions, without unchecking the auth user. Screenshot attached.

Therefore, the Logintoboggon pre-auth logic is pointless... The solutions is to ass a 'verified role', like this
#628334: Assign role on account confirmation

CommentFileSizeAuthor
authenticated.jpg16.04 KBAnonymous (not verified)

Comments

Anonymous’s picture

Status: Active » Closed (works as designed)

Ok, it does work as designed. First set the the role, then configure permissions. Thanks!

Anonymous’s picture

Issue summary: View changes

Updated issue summary.