0
0
mirror of https://github.com/postfixadmin/postfixadmin.git synced 2024-09-19 19:22:14 +02:00

see https://github.com/postfixadmin/postfixadmin/issues/683 - add in error_log for e.g. fail2ban to pick up on someone trying to get into setup.php

This commit is contained in:
David Goodwin 2022-11-15 16:33:49 +00:00
parent 78174d8f67
commit 9fbb2fcc14

View File

@ -81,6 +81,7 @@ if (strlen($configSetupPassword) == 73 && strpos($configSetupPassword, ':') == 3
if (password_verify(safepost('setup_password', 'invalid'), $configSetupPassword)) {
$authenticated = true;
} else {
error_log("PostfixAdmin setup login failed (ip_address: {$_SERVER['REMOTE_ADDR']})");
$errors['setup_login_password'] = "Password verification failed.";
}
}