We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 19562
    • 18 Posts
    Hi all,

    Forgive me if i’am mistaken but i think there are a few faults in the weblogin.processor.inc.php code (version 1.0. Actual version as far as i know) :
    (I don’t not whether this is discussed somewhere earlier but here are my comments)

    	if(isset($newloginerror) && $newloginerror==1) {
    		$failedlogins += $newloginerror;
    		if($failedlogins>=3) { //increment the failed login counter, and block!
    			$sql = "update $dbase.".$table_prefix."web_user_attributes SET failedlogincount='$failedlogins', blockeduntil='".(time()+(1*60*60))."' where internalKey=$internalKey";
    			$ds = $modx->dbQuery($sql);
    		} else { //increment the failed login counter
    			$sql = "update $dbase.".$table_prefix."web_user_attributes SET failedlogincount='$failedlogins' where internalKey=$internalKey";
    			$ds = $modx->dbQuery($sql);
    		}
    		session_destroy();
    		session_unset();
    		return;
    	}
    


    Two things i found are:
    1. The failed login counter is incremented after a (hardcoded) amount of 3 attempts instead of the amount specified in the manager.
    2. All session variables will be lost after the first time a user gives a wrong password/username combination. In scenarios where session variables are used for storing i.e. shopping basket contents this is a litte irritating..

    Please correct me if i’am wrong..
      "Just smile and wave boys..smile and wave"
      • 7455
      • 2,204 Posts
      I use sessions for a shop and after loging in as webuser the session is still there. even if I make a mistake. But when I logout the session is gone.
      When I log in as manager all sessions are gone.

      Dimmy
        follow me on twitter: @dimmy01