Stop administrator login
An administrator account could bypass the login block by using alternative authentication methods. They could view all private user details and change any site settings. They could not bypass the block without a valid administrator password.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if an attacker has a valid administrator password and uses a less common login method.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Stop administrator login to 8.x-1.6.
For developers: what the fix changed
The fix transitions the module from using `hook_form_alter` to using an event subscriber (`AuthenticationCheckSubscriber`) and a service decorator (`UserAuthentication`) to enforce login restrictions across all authentication mechanisms. It also introduces a `LoginPolicy` service to centralise the restriction logic.
Also in this release Updated core version requirements to Drupal 10.3 and 11, updated documentation, and added test coverage.
README.md+44 −6src/EventSubscriber/AuthenticationCheckSubscriber.php+94 −0 fixsrc/Form/StopAdminConfigForm.php+1 −3src/LoginPolicy.php+62 −0 fixsrc/UserAuthentication.php+64 −0 fixstop_admin.info.yml+1 −1stop_admin.module+34 −43 fixstop_admin.services.yml+13 −0 fix