Login link in mail has to many parameters does not work with 7G firewall
-
Hello friends,
I have noticed something interesting that I would like to share with you.
The last, including the current “Magic Login” versions has a problem with Firewall 7G.We also have the 7G firewall (from Jeff Starr) active on NGINX servers for WordPress installations and for a few weeks now this “Magic Login link” sent in the mail no longer works because said 7G prevents it. This behavior was probably triggered by security updates from Debian and NGINX, which is correct and desired.
Now I have installed an older “Magic Login” version 1.7 and lo and behold, this version works perfectly with the 7G firewall.
Why is that? Well, I investigated and found it.
The link sent by “Magic Login” in version 1.7 does not contain any attached parameters with “&”, but only “?magic-login=1”.
You can even omit the parameter “?magic-login=1” completely, so that only the hashed token in the link works for login.
It may be because the “&” character is not quoted correctly or not quoted at all, or the “https://”, or another character. But it could also be that the attached parameters are simply too long. My tests are not 100% clear.It would be excellent if you could investigate my concern and fix this in future versions.Otherwise, great plugin, keep it up and best regards and good luck
Thank You
Jan
- The topic ‘Login link in mail has to many parameters does not work with 7G firewall’ is closed to new replies.