Hi all,
Forgive me if i’am mistaken but i think there are a few faults in the weblogin.processor.inc.php code (version 1.0. Actual version as far as i know) :
(I don’t not whether this is discussed somewhere earlier but here are my comments)
if(isset($newloginerror) && $newloginerror==1) {
$failedlogins += $newloginerror;
if($failedlogins>=3) { //increment the failed login counter, and block!
$sql = "update $dbase.".$table_prefix."web_user_attributes SET failedlogincount='$failedlogins', blockeduntil='".(time()+(1*60*60))."' where internalKey=$internalKey";
$ds = $modx->dbQuery($sql);
} else { //increment the failed login counter
$sql = "update $dbase.".$table_prefix."web_user_attributes SET failedlogincount='$failedlogins' where internalKey=$internalKey";
$ds = $modx->dbQuery($sql);
}
session_destroy();
session_unset();
return;
}
Two things i found are:
1. The failed login counter is incremented after a (hardcoded) amount of 3 attempts instead of the amount specified in the manager.
2. All session variables will be lost after the first time a user gives a wrong password/username combination. In scenarios where session variables are used for storing i.e. shopping basket contents this is a litte irritating..
Please correct me if i’am wrong..