I run a private server and the whitelist has been changed a few times. In this case, the player "mafew" has been removed from the whitelist long ago (~6 months or so).
Earlier today, he notified me that he could still join the server, though he shouldn't be able to.
I confirmed that yes, the whitelist was on, and that he wasn't on the whitelist, as seen in the serverlog extract below:
—
whitelist on
2012-12-24 23:00:37 [INFO] Turned on the whitelist
whitelist reload
2012-12-24 23:00:41 [INFO] Reloaded the whitelist
whitelist list
2012-12-24 23:00:43 [INFO] There are 8 (out of 10 seen) whitelisted players:
2012-12-24 23:00:43 [INFO] doublebeta, jett14, airtay, fastred_007, moorley, em_rose, thegoogletaco and xeon927
2012-12-24 23:00:48 [INFO] mafew/60.242.210.32:65383 logged in with entity id 640641 at (-65.12565206501867, 10.0, 231.52402714369583)
—
I'm taking a wild guess here in that due to the player being on the whitelist previously (seen above with "There are 8 (out of 10 seen) whitelisted players:"), access is still being given, which it shouldn't.
Restarting the server does not solve the issue.
Nevermind. Found the problem. The user was also (for some reason or another) listed in the ops.txt file.
Deopped the player, and everything is functioning as it should now. This issue can be closed.