Bug #18287


2FA subdomain login takes me to home page from arbitrary page

Added by Raffi Khatchadourian 4 months ago. Updated 3 months ago.

Priority name:
Category name:
Target version:
Start date:
Due date:
% Done:


Estimated time:
Deployment actions:


  1. As an unauthenticated user, visit
  2. Click on the login box on the top right.
  3. Enter credentials
  4. Enter 2FA code.

Expected Result
After successfully entering the 2FA code, I should be redirected to

Actual Results
I am taken to

Related to

Actions #1

Updated by Raymond Hoh 4 months ago

  • Category name set to Authentication
  • Status changed from New to Staged for Production Release
  • Assignee set to Raymond Hoh
  • Target version set to 2.1.8

Thanks for the report and the steps to duplicate, Raffi.

This is related to a fix done for #3376: That fix disregards the login redirect URL and would force the redirect URL to be either the site's home URL or the site's admin dashboard depending on the user's role.

I've added a fix to allow the redirect URL through if not accessing the admin dashboard. (Code reference - .) This is scheduled to be part of the next maintenance release on June 13th.

Boone, the code also fixes some issues with checking the redirect URL after successful login. Since we force logins to the main site if not using the admin bar login, the older code to bypass the main site would not do checks against the redirect URL. In the fix, we're now checking the redirect URL to see if the redirect URL is for the admin dashboard and if the user has the correct capabilities for the site in question. We were previously using the 'edit_posts' capability for the permission check, but I've decided to go one step lower and allow the 'publish_posts' capability as well. This should make things easier for users accustomed to going directly to, especially users with the 'author' role.

Actions #2

Updated by Boone Gorges 4 months ago

Thanks, Ray!

Actions #3

Updated by Boone Gorges 3 months ago

  • Status changed from Staged for Production Release to Resolved

Also available in: Atom PDF