Uploaded image for project: 'phpBB3'
  1. phpBB3
  2. PHPBB3-13204

Login flood control error supresses incorrect credential error

    Details

    • Type: Bug
    • Status: Unverified Fix
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 3.1.0-RC5
    • Fix Version/s: 3.1.2-RC1
    • Component/s: None
    • Labels:
      None

      Description

      Entering an incorrect username/password combination into the login form produces the expected "you have specified an incorrect password..." message.

      However, once this is done several times and the flood controls kick in, that message is no longer displayed.

      The matter becomes especially unclear to the user if it was someone else who triggered the flood control in the first place. When the real account owner attempts to login (with an invalid password), they are repeatedly told to fill in the CAPTCHA, but never told that their password isn't correct.

        Activity

        There are no comments yet on this issue.

          People

          • Assignee:
            Marc Marc
            Reporter:
            Marshalrusty Yuriy Rusko
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development