I have a weird conflict with logintoboggan: I allow users to login, but their email address must be validated. They get a special role, "unverified", and not the "authenticated user" role.

With remember_me enabled, all these users get the "authenticated user" role regardless.

Switched to persistent_login, that fixed the problem.

Comments

nickl’s picture

@berenddeboer is this custom module code that you wrote or some way that you can configure logintoboggan?

nickl’s picture

If it is their hook_user_load(). implementation which you are referring to.

// 1063 logintoboggan.module
/**
  * Implement hook_user_load().
  */
 function logintoboggan_user_load($users) {
   foreach ($users as $account) {
     // If the user has the pre-auth role, unset the authenticated role
     _logintoboggan_user_roles_alter($account);
   }
 } 
// 1073

I can't think of anything we are doing which will prevent that from firing.

loze’s picture

Issue summary: View changes

this is also happening for me.

loze’s picture

I believe this is caused when remember_me sets the session in _remember_me_set_lifetime.
I was able to fix this by adding the following to the end of that function after drupal_session_initialize();

  if(module_exists('logintoboggan')){
    _logintoboggan_user_roles_alter($GLOBALS['user']);
  }