User Management Bug - deleted users still log in/access projects

Briefly describe (1-2 sentences) the Bug you’re experiencing:
deleted users can still log in, deleted users that were re-invited with a different email address can still see two IDs under their icon, can switch between them even though only one user appears in member list.

Steps to reproduce:

  1. created a user, assigned to teams/projects. They had no trouble accessing those projects
  2. deleted users, re-invited them with a new email address (diff corp division, they only need to be ‘observers’, not active users).
  3. original email address clearly not showing in member list
  4. user tries to log in with new address. does not see any teams or projects, despite my seeing them assigned to teams in the member admin section
  5. user sees two accounts under their user icon in the upper right hand corner - user can switch to the deleted account and see teams and projects, even though that user has been deleted
  6. tried this with multiple browsers, all cache and cookies cleared. In at least one case, user tried with a browser (Edge) that he had literally never used for anything before, yet it still logged him in and showed both the current account and the deleted account - so that is obviously a back end/data base problem, not a user error or a browser issue.

Browser version:

  • chrome, firefox, edge (whatever the current release of all of them is)

Upload screenshots below:

@Julien_RENAUD you played a lot with accounts and emails recently, any input on this thread?

I’ve never had this problem, no idea…

Hi @anon62472401, thanks for reaching out!

If you have an Organization, it seems you deleted the user from a team and not from the entire Organization and for this reason they still appear as members. Please note we currently not offer view only access in Asana and the members you add to your Workspace or Organization will have access to public projects and private projects you shared with them.

In order to investigate this further, I recommend you to contact our support team and share this information:

  • URL of this thread
  • Email address of the user who was removed but still can access your Organization

Unfortunately I don’t have the tools in the forum to have a closer look, our support team is in a better position to give you a tailored answer here :slight_smile:

I hope the issue is solved soon!

Good idea, but no. We only have one organization, and they were deleted off the Admin > Members screen, not just deleted out of a team.

Derek

This topic was automatically closed 16 days after the last reply. New replies are no longer allowed.