Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-13204

Login flood control error supresses incorrect credential error

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • 3.1.2-RC1
    • 3.1.0-RC5
    • None
    • None

      Entering an incorrect username/password combination into the login form produces the expected "you have specified an incorrect password..." message.

      However, once this is done several times and the flood controls kick in, that message is no longer displayed.

      The matter becomes especially unclear to the user if it was someone else who triggered the flood control in the first place. When the real account owner attempts to login (with an invalid password), they are repeatedly told to fill in the CAPTCHA, but never told that their password isn't correct.

            Marc Marc
            Marshalrusty Yuriy Rusko
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: