[D7] Nothing clears the "5 failed login attempts" security message when a user resets their own password

Created on 23 May 2017, about 7 years ago
Updated 13 November 2023, 7 months ago

Problem/Motivation

7.x port of πŸ› Nothing clears the "5 failed login attempts" security message when a user resets their own password Fixed (8.3.x & 8.4.x)

If a user forgets their password and tries to log in 5 times then they get blocked by flood control. They can now use the password reset functionality per email, but once they log out shortly after that they are still blocked when trying to log in again.

Proposed resolution

Clear the user specific flood events once they used the password recet functionality so that they are able to normally log in again. Do not clear IP address specific flood events because then an attacker with a valid account could clear flood events for victim user accounts.

Remaining tasks

Update and review the patch.

πŸ› Bug report
Status

Fixed

Version

7.0 ⚰️

Component
User systemΒ  β†’

Last updated 3 days ago

Created by

πŸ‡¬πŸ‡§United Kingdom vijaycs85 London, UK

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.69.0 2024