Admin Login Fails Only After Time Has Passed Since Logging Out
-
Usually, when I logout, wait awhile and then try logging in, I enter my username and password, verifying both are correct, click the Log in button, and the system works perfectly, informing me that my password or username are incorrect. It is absolutely beautiful, because I have done a few things to make it impossible to have submitted the incorrect username and password. So then I click the forgot password link, open email, click the password reset link contained therein, which takes me to a form on my site for resetting the password. I replace the suggested password with the one I have been using since installing WordPress, it gives me a notice saying the password is changed. Then I click on the link to bring up the login screen (prompting me to wonder why changing the password does not log me in as part of the process of changing the password, assuming there is a security best practice demamding that WordPress could never login at the end of the password change process, about which I wonder and cannot resist doubting the need), enter the same username and password that had not been working and just like that, I am logged in.
What can I do to prevent being forced to change my password in order to login?
My personal preference is to always be forced to change my password, but some of the people I work for have requested I eliminate that step, except for any and all use cases involved in the response to losing a password. In those cases, changing the password is considered within my user community to be a net positive, at least until I can provide them an application that prevents users from forgetting their passwords.
Bottom line, is there anything I can do to prevent the system from forcing a password change, and if so, what is it?
The page I need help with: [log in to see the link]
- The topic ‘Admin Login Fails Only After Time Has Passed Since Logging Out’ is closed to new replies.