- ⌂ io_comand_login
- Classes
- Content Types
Base Login Controller
The Base Login Controller content type has the following fields and is meant to be extended to implement specific Login Policy Controllers: Login, Change, Reset, Unlock and Logger.
- Title - Human-friendly name.
- Description - Short description of the controller and how it can be used.
- Package - Defines the package that the class implementation is in for this feature. If not specified, defaults to the content type PHP implementation.
- Class Name - Defines the fully qualified class name that this class implementation is in for this feature. If not specified, defaults to the content type PHP implementation.
- Thresholds - Defines failure attempt thresholds that will result in locking the system for a particular user account, IP address, etc. Options include:
- Account Attempt Threshold - Defines an attempt threshold for an individual user account. In other words, if a login is attempted for a specific username beyond the threshold, further login attempts for that username will be blocked.
- IP Attempt Threshold - Defines an attempt threshold for an individual IP address. In other words, if a login is attempted from a specific IP address beyond the threshold, further attempts from the IP address will be blocked.
- IP/User Agent Attempt Threshold - Defines an attempt threshold for an IP address and User Agent combination. In other words, if a login is attempted from a specific IP address and user agent beyond the threshold, further attempts from the same IP address and user agent will be blocked.
Attempt Thresholds
Each of the thresholds described above include the following options.
- Number - The number of attempts that meets the threshold, given the configured Seconds. For example, Number(3) and Seconds(30) means that 3 consecutive failed attempts over 30 seconds meets the configured threshold.
- Seconds - The timeframe that meets the threshold, given the configured Number. For example, Number(3) and Seconds(30) means that 3 consecutive failed attempts over 30 seconds meets the configured threshold
- Period - The period of time (in seconds) the threshold will remain 'active' once reached; that is, a Period of 300 means that once met, the threshold will remain met for 5 minutes before naturally expiring. A period of 0 means that the threshold will remain permanently met, and must be unlocked manually.
- Include Success - Attempt thresholds by default only count failed attempts to prevent brute force attacks on a system. Check this box to include all attempts against a controller, serving as a throttle for bot attacks against controllers such as creating new users, which has no failure condition.
webCOMAND Docs