• Resolved esspeedee

    (@esspeedee)


    Hi,
    I really like this plugin, thanks. I have it on 4 sites.

    However, over the last 2 weeks (approx) I have been experiencing login problems on all of the sites.
    The standard wordpress userid and password screen is OK, but the two-factor authentication screen fails to load. The screen is partially loaded but the form and submit button are not visible. A little rotation icon is in the tab….
    The sites have different mail services so it mail servers are not the problem.
    The authentication email arrives (sometimes it takes a while), but there is no screen to enter the code!!
    I’ve tried Chrome, Edge and IE.
    Here is the thing – sometimes it does load, sometimes it loads after a long wait, but mainly it just never loads – it just hangs with its spinning tab icon.
    I have V0.7.0, and wordpress (mixed between 5.2 and 5.7) and PHP versions 7.2 are OK I believe.

    I don’t want to disable the plugin as its a good security service.

    Any ideas how I go about diagnosing / fixing this?

    Thank you, and thanks again for a great plugin.

Viewing 4 replies - 1 through 4 (of 4 total)
  • Thread Starter esspeedee

    (@esspeedee)

    This update might help:
    After trying for some days to fix this, it seems like ModSecurity could be involved.

    If I disable ModSec the Two Factor plugin works.

    However, with ModSec enabled, the first loading of wp-login.php (with the userid and password) loads OK, but the second loading of wp-login.php which is asking for the 2FA code fails to load fully. It seems to load about 50% of the page then just stops.
    The submit section and the javascript part of the 2FA form do not load.

    This has only just started happening. I wonder if there has been a recent update to ModSec?

    I cannot say for sure if ModSec is blocking it. But with the limited access I have to the host server, it looks like it could be contributing.

    I hope this helps. I would greatly appreciate any feedback or help with this issue, please?

    Thanks

    Plugin Author Kaspars

    (@kasparsd)

    This appears to be an integration issue with the specific ModSec plugin. Maybe other users of the same plugin can help debug this further.

    WordPress login workflow is relatively restrictive for extensibility so ensuring compatibility between several plugins that modify the default login behaviour is really hard.

    Thread Starter esspeedee

    (@esspeedee)

    Hi,
    Thanks for the update.

    The hosting company and I spent a log time trying to get this to operate. They could not identify (in the event log) the specific modsec rule being triggered.
    What we (as best as we could) confirmed is that ModSec is blocking the reload of login.php.

    In the end, I have to replace the plugin with a similar plugin from bestwebsoft. That plugin works really well. In essence it doesn’t (seem) to reload login.php. So modsec cannot block any reload.

    But thanks for the plugin. It has been terrific, but sadly we could not continue with modsec disabled.

    Regards and thanks again,

    I use Modsec on my server and I am about to install and test this plugin for a client, so this is a helpful support thread. I will update this once I have a report.

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘authentication screens hangs’ is closed to new replies.