Login Disable
This module stops people from logging in to the website unless they know a secret code to add to the web address.
A person with an ordinary account on the site can log in using a specific web address without needing the secret code. They cannot read any extra information. They cannot change anything on the site.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this less critical. Fix it with the next routine update.
Tell your developerUpdate Login Disable to 2.1.3.
For developers: what the fix changed
The fix adds a route subscriber in `src/EventSubscriber/LoginDisableRouteSubscriber.php` to attach a custom access check to the `user.login.http` route. The access check, implemented in `src/Access/LoginDisableAccessCheck.php`, verifies that the required access key is present in the request URL before allowing login.
Also in this release Added automated tests for the HTTP login functionality.
login_disable.services.yml+13 −0 fixsrc/Access/LoginDisableAccessCheck.php+58 −0 fixsrc/EventSubscriber/LoginDisableRouteSubscriber.php+23 −0 fix