6.0.0-alpha12
6/6/25

[#11601] User is not authorized for horde
Summary User is not authorized for horde
Queue Horde Framework Packages
Queue Version Git master
Type Bug
State Not A Bug
Priority 1. Low
Owners
Requester Twilek (at) gmx (dot) de
Created 10/31/2012 (4601 days ago)
Due
Updated 07/03/2013 (4356 days ago)
Assigned
Resolved 10/31/2012 (4601 days ago)
Milestone
Patch No

History
07/03/2013 08:28:50 PM horde_mailinglist (at) der-domi (dot) de Comment #12 Reply to this comment
Hey,

I seen the messages too. I repoduced it with setting
     $conf[auth][redirect_on_logout] = true;
an press the logout button. Then I get the message.

And when I login again I get sometime an "404 file not found" error.

Could it be that this is coherent with your views?
03/13/2013 12:10:37 PM arjen+horde (at) de-korte (dot) org Comment #11 Reply to this comment
The problem is that this is not a sufficient priority to be able to 
easily catch brute-force attacks on a system.
While I agree that one wants to be alerted when a brute-force attack 
is ongoing, logging every failed connection with a severity EMERG is 
just not what administrators expect. See RFC 5424:

      Numerical       Severity
         Code
               0       Emergency: system is unusable
               1       Alert: action must be taken immediately
               2       Critical: critical conditions
               3       Error: error conditions
               4       Warning: warning conditions
               5       Notice: normal but significant condition
               6       Informational: informational messages
               7       Debug: debug-level messages

               Table 2. Syslog Message Severities
So you set it to a lower level and then someone can hammer your box 
1,000,000 times an hour and you won't see anything in your logs. Bad 
idea.
I'd prefer that over having to explain to administrators that they 
don't have to worry about messages being logged with severity EMERG.

From http://en.wikipedia.org/wiki/Syslog

Emergency - A "panic" condition usually affecting multiple 
apps/servers/sites. At this level it would usually notify all tech 
staff on call.
03/12/2013 09:03:24 PM Michael Slusarz Comment #10 Reply to this comment
The problem is that this is not a sufficient priority to be able to 
easily catch brute-force attacks on a system.

So you set it to a lower level and then someone can hammer your box 
1,000,000 times an hour and you won't see anything in your logs.  Bad 
idea.
03/12/2013 08:49:46 PM arjen+horde (at) de-korte (dot) org Comment #9 Reply to this comment
So what?  They are just informative log entries.  They don't 
indicate anything is wrong.
In that case it might be better to lower the priority with which they 
are logged from EMERG to INFO.
03/12/2013 08:47:36 PM michael (dot) groene (at) zel (dot) uni-hannover (dot) de Comment #8 Reply to this comment
I felt a bit uncomfortable with a log full with messages of severity 
"emergency".
03/12/2013 08:41:08 PM Michael Slusarz Comment #7 Reply to this comment
So what?  They are just informative log entries.  They don't indicate 
anything is wrong.
03/12/2013 08:37:17 PM michael (dot) groene (at) zel (dot) uni-hannover (dot) de Comment #6 Reply to this comment
Our log is full with these entries, too.  No idea why and how to reproduce...
11/06/2012 09:45:15 AM Twilek (at) gmx (dot) de Comment #5 Reply to this comment
I have just checked horde“s log and can confirm this.

[Show Quoted Text - 9 lines]
11/06/2012 09:38:08 AM software-horde (at) interfasys (dot) ch Comment #4 Reply to this comment
This is still happening on rare occasions, so I'm guessing it only 
affects some users

2012-11-05T10:43:05+01:00 EMERG: HORDE User is not authorized for 
horde [pid 70549 on line 259 of "/usr/local/lib/php/Horde/Registry.php"]
2012-11-05T10:43:05+01:00 DEBUG: HORDE 1. Horde_Registry::appInit() 
/var/www/html/webmail/rampage.php:54

10/31/2012 10:48:01 AM Jan Schneider State ⇒ Not A Bug
 
10/31/2012 08:32:38 AM Twilek (at) gmx (dot) de Comment #3 Reply to this comment
I can confirm the exact same behaviour.

Message is printed 3 times at each login.
The " pear install -f horde/Horde_Core" seemed to have fixed that as well
10/31/2012 01:58:35 AM software-horde (at) interfasys (dot) ch Comment #2 Reply to this comment
I can confirm the exact same behaviour.

Message is printed 3 times at each login.
10/31/2012 12:09:20 AM Twilek (at) gmx (dot) de Comment #1
State ⇒ Unconfirmed
Patch ⇒ No
Milestone ⇒
Queue ⇒ Horde Framework Packages
Summary ⇒ User is not authorized for horde
Type ⇒ Bug
Priority ⇒ 1. Low
Reply to this comment
I have upgraded my horde 4 to horde 5 (webmail edition). After the 
upgrade whenever I login or logout horde throws an "EMERG: HORDE User 
is not authorized for horde [pid xxx on line 259 of 
"/usr/share/php/Horde/Registry.php"]"

I use IMP (against my IMAP) Server for authorization...

There is no user "HORDE" in my system

Saved Queries