Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] Disable brute force authentication security checks for specific IP addresses not possible? #22953

Open
4 tasks done
elitza-vasileva opened this issue Jan 20, 2025 · 4 comments
Labels
Potential Bug Something that might be a bug, but needs validation and confirmation it can be reproduced. To Triage An issue awaiting triage by a Matomo core team member

Comments

@elitza-vasileva
Copy link

What happened?

I have blocked myself for logging into Matomo due to too many failed logins.

What should happen?

I then read this documentation about how to disable the brute force authentication security check for my IP address: https://matomo.org/faq/troubleshooting/faq_32758/

I tried to follow the instructions there and logged in to Matomo via my phone, but the described option was not available:

Image

How can this be reproduced?

I went to our self-hosted Matomo URL -> Administration -> System -> General Settings -> Login

As mentioned above: the "Never block these IPs from logging in" does not exist. The same issue when I log in on my phone where I use a different browser.

Matomo version

5.2.1

PHP version

8.3.10

Server operating system

Linux

What browsers are you seeing the problem on?

Chrome

Computer operating system

Windows

Relevant log output

Validations

@elitza-vasileva elitza-vasileva added Potential Bug Something that might be a bug, but needs validation and confirmation it can be reproduced. To Triage An issue awaiting triage by a Matomo core team member labels Jan 20, 2025
@elitza-vasileva elitza-vasileva changed the title [Bug] [Potential Bug] Disable brute force authentication security checks for specific IP addresses Jan 20, 2025
@elitza-vasileva elitza-vasileva changed the title [Potential Bug] Disable brute force authentication security checks for specific IP addresses [Bug] Disable brute force authentication security checks for specific IP addresses not possible? Jan 20, 2025
@sgiehl
Copy link
Member

sgiehl commented Jan 20, 2025

Hey @elitza-vasileva. Thanks for the report.
For me that actually looks like expected and the option is available.
Are you maybe seeing any errors in your browser console or similar?

@randy-innocraft
Copy link

Hi @elitza-vasileva,
Could you please let me know if your user account has the role of Superuser?

@elitza-vasileva
Copy link
Author

Hey @elitza-vasileva. Thanks for the report. For me that actually looks like expected and the option is available. Are you maybe seeing any errors in your browser console or similar?

Hi @sgiehl. No, I do not see any errors in the console or elswhere. One thing that might be a useful information is that I am logged in via http and not https, because we still haven't set up our own damin to make the connection secure.

@elitza-vasileva
Copy link
Author

Hi @elitza-vasileva, Could you please let me know if your user account has the role of Superuser?

Yes, the account I am logged in with has the Superuser role.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Potential Bug Something that might be a bug, but needs validation and confirmation it can be reproduced. To Triage An issue awaiting triage by a Matomo core team member
Projects
None yet
Development

No branches or pull requests

3 participants