Nested password protected pages

Permalink Browser Info Environment
I'm having an issue with the following setup:

I have a page with a password set on it and it works fine.

I have another page, which is a subpage of the first page. This page has it's own separate password. That works fine.

However, if you sign in to the parent page, you will automatically have access to the subpage, despite the fact that the subpage's separate password was never entered.

Neither page is set up to have recursive passwords.

Type: Pre-Sale
Status: In Progress
frankdesign
View Replies:
hanicker replied on at Permalink Reply
hanicker
Hi, this should happen if the password is the same. Can you confirm that those pages do not share the same password?

Thanks
Regards

Nicola
frankdesign replied on at Permalink Reply
frankdesign
They do not share the same password.
frankdesign replied on at Permalink Reply
frankdesign
Any updates on this? I haven't had much luck myself yet.
hanicker replied on at Permalink Reply
hanicker
Sorry for this really late reply. Is recursive mode checkbox disabled on the parent page?
Thanks
Regards

Nicola

concrete5 Environment Information

# concrete5 Version
5.6.1.2

# concrete5 Packages
Add Multiple Pages (2.1.1), Designer Content (3.1.1), Honeypot (1.0), List files from set (1.0.4), Page password (1.1.4), Pro Events (9.5.2), Subscribe Users (1.0.0), Tweetcrete (1.6.6).

# concrete5 Overrides
blocks/page_list, blocks/form, blocks/list_files_from_set, blocks/content, blocks/link_to_page, blocks/regions, blocks/map_regions, blocks/dashboard_app_status, blocks/user_subscriptions, blocks/search, blocks/image, blocks/file, blocks/banner_slide_standard, blocks/jereme_tweetcrete, blocks/autonav, blocks/content_divider, elements/dashboard, elements/header_required.php, elements/page_controls_header.php, helpers/concrete, css/images, css/ccm.app.css, mail/block_guestbook_notification.php, mail/block_form_submission.php, single_pages/dashboard, single_pages/login.php, single_pages/page_not_found.php, themes/dashboard, themes/site, tools/page_controls_menu_js.php

# Server Software
Apache/2.4.25 (cPanel) OpenSSL/1.0.1e-fips mod_bwlimited/1.4

# Server API
cgi-fcgi

# PHP Version
5.5.38

# PHP Extensions
bcmath, calendar, cgi-fcgi, Core, ctype, curl, date, dom, ereg, filter, ftp, gd, hash, iconv, imap, json, libxml, mbstring, mcrypt, mhash, mysql, mysqli, mysqlnd, openssl, pcntl, pcre, PDO, pdo_mysql, pdo_sqlite, Phar, posix, readline, Reflection, session, SimpleXML, sockets, SPL, sqlite3, standard, tokenizer, wddx, xml, xmlreader, xmlwriter, xsl, zip, zlib.

# PHP Settings
max_execution_time - 90
log_errors_max_len - 1024
max_file_uploads - 20
max_input_nesting_level - 64
max_input_time - 60
max_input_vars - 1000
memory_limit - 512M
post_max_size - 8M
sql.safe_mode - Off
upload_max_filesize - 10M
mysql.max_links - Unlimited
mysql.max_persistent - Unlimited
mysqli.max_links - Unlimited
mysqli.max_persistent - Unlimited
pcre.backtrack_limit - 1000000
pcre.recursion_limit - 100000
session.cache_limiter - nocache
session.gc_maxlifetime - 7200

Browser User-Agent String

Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36

Hide Post Content

This will replace the post content with the message: "Content has been removed by an Administrator"

Hide Content

Request Refund

You have not specified a license for this support ticket. You must have a valid license assigned to a support ticket to request a refund.