Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 294806

User login flood lock doesn't clear when reset password as admin

$
0
0

Problem/Motivation

#992540: Nothing clears the "5 failed login attempts" security message when a user resets their own password clears the user login flood lock when user try to reset password. However, it doesn't work for admin resets user password.

Steps to reproduce

  1. Register as a normal user
  2. Try to login with wrong password for 5 times
  3. Login as admin and change user's password
  4. Try to login as user with new password

Expected
Allow user to login with new password.

Expected
- Still getting "There have been more than 5 failed login attempts for this account. It is temporarily blocked. Try again later or request a new password."

Proposed resolution

Dispatch an event on password reset to clear flood lock.

Remaining tasks

- One scenario current patch doesn't work - When admin reset the password and new password == old password.


Viewing all articles
Browse latest Browse all 294806

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>