19228Bug reportsAuthenticationpublic2023-11-27 09:51
Reporterc_schmitz Assigned ToDenisChenu  
Status closedResolutionfixed 
Summary19228: Setting Bruteforce timeout values to empty string causes the administrator to be locked out

Setting Bruteforce timeout values to empty string causes the administrator to be locked out

Steps To Reproduce

Steps to reproduce

In general settings remove the timeout & retry values for administration/survey participants and save.

Expected result

You should not be able to save, you should be forced to give a positive integer number >=0.

Actual result

You can save. After logging out you are unable to log in, anymore.

2023-11-09 10:12

developer   ~78351

0 or "" can just disable ?

Maybe adding a placeholder ? With min=1

<input placeholder="disable" class="form-control" min="1" type="number" name="maxLoginAttemptParticipants" value="3">

Something like this



2023-11-09 16:22

developer   ~78353

I can not reproduce on last 5 and 6 ?



2023-11-09 16:22

developer   ~78354

2023-11-13 14:15

manager   ~78412

@DenisChenu seems you have already been digging on this.
Are you taking it or prefer me to take it?



2023-11-13 15:07

developer   ~78418

@gabrieljenik : i just can not reproduce …



2023-11-13 20:32

manager   ~78439

I couldn't reproduce it either.

We can still add those validations using the html5 attribute min=0



2023-11-14 08:33

developer   ~78442

We can still add those validations using the html5 attribute min=0

0 for time in second (then reset each time)
1 for max number + integer
and disable for placeholder : i take it.



2023-11-14 10:03

developer   ~78447

Last edited: 2023-11-14 10:10

I can reproduce for Token part (debug = 2)

2023-11-14 10:52

developer   ~78448

This commit

Fix an XSS by superadmin to other superadmin



2023-11-14 12:32

developer   ~78451

5.X :
master :



2023-11-20 13:35

administrator   ~78536

@DenisChenu There is an issue on master and 5.x. When I type in some values and save, the values become 1.



2023-11-20 16:34

developer   ~78548

Oups … sorry … really sorry …

Must be fixed now …



2023-11-23 16:39

developer   ~78689

Fix committed to 5.x branch:



2023-11-23 16:41

developer   ~78691

Fix committed to master branch:



2023-11-27 09:51

administrator   ~78719

Fixed in Release 6.3.7+231127

