Yannick Warnier
c28eecb18d
Global: Fix CAPTCHA image missing in registration and lost password pages - refs #3839
...
Squashed commit of the following:
commit 48538d6c59e5adac9ec9703fe35ae498d40d4792
Author: Yannick Warnier <ywarnier@beeznest.org>
Date: Wed Aug 11 01:02:56 2021 +0200
Minor - Code styling
commit ebfb1db3aec7ec5b8410f3f7a260fb2dfe4209c8
Merge: 899bfcfe76 5c946a9b44
Author: Yannick Warnier <ywarnier@beeznest.org>
Date: Wed Aug 11 00:59:03 2021 +0200
Merge branch '3839' of https://github.com/christianbeeznest/chamilo-lms into 3839
commit 5c946a9b44
Author: Christian <christian1827@gmail.com>
Date: Tue May 25 19:02:23 2021 -0500
Fix captcha image is not displayed in lost password and inscription pages - refs #3839
commit b2ac9da2ad
Merge: e07a555432 615b90bd41
Author: Christian <christian1827@gmail.com>
Date: Tue May 25 18:49:54 2021 -0500
Merge branch '1.11.x' of https://github.com/chamilo/chamilo-lms into 1.11.x
commit e07a555432
Merge: 44251f9d10 a562622d50
Author: Christian <christian1827@gmail.com>
Date: Fri May 21 14:51:16 2021 -0500
Merge branch '1.11.x' of https://github.com/chamilo/chamilo-lms into 1.11.x
commit 44251f9d10
Merge: b06bdd0a50 9d41b63eb5
Author: Christian <christian1827@gmail.com>
Date: Fri May 21 10:51:30 2021 -0500
qMerge branch '1.11.x' of https://github.com/chamilo/chamilo-lms into 1.11.x
commit b06bdd0a50
Merge: f35edf31a4 7e3f9afbd1
Author: Christian <christian1827@gmail.com>
Date: Fri May 21 05:50:29 2021 -0500
Merge branch '1.11.x' of https://github.com/chamilo/chamilo-lms into 1.11.x
commit f35edf31a4
Merge: d43e3a5f2e 905a21037e
Author: Christian <christian1827@gmail.com>
Date: Thu May 20 15:05:44 2021 -0500
Merge branch '1.11.x' of https://github.com/chamilo/chamilo-lms into 1.11.x
commit d43e3a5f2e
Author: Christian <christian1827@gmail.com>
Date: Wed May 19 17:34:20 2021 -0500
Fixed Document tool : pagination broken #3748
4 years ago
Alex Aragon
68ee8f319e
fix css
5 years ago
Alex Aragon
7d62ad717b
improvement for custom pages, with template
5 years ago
Julio Montoya
64a0ec0786
Minor - format code
6 years ago
Julio Montoya
b69fb3a089
Fix wrong redirection when using custom pages + show flash messages
...
BT#17022
6 years ago
Julio Montoya
f096db8f51
Minor - format code
6 years ago
Angel Fernando Quiroz Campos
6fbf41c2a4
Plugin: Whispeak delete wsid when requesting restore password - refs BT#15813
7 years ago
Julio Montoya
ecdc2037e2
Applied fixes from FlintCI
8 years ago
Julio Montoya
bf885f42f4
Applied fixes from FlintCI
8 years ago
jmontoyaa
cd0d11d17a
Remove useless templates, replaced with common template.
...
By common I mean the use of $template->display_one_col_template();
8 years ago
jmontoyaa
786078efd2
Remove unused parameter
8 years ago
jmontoyaa
35cd3b5c08
Use api_get_user_entity()
...
- Format code
- First send email, then put user as inactive.
8 years ago
jmontoyaa
d9623f75b9
Minor - format code
9 years ago
Rafa
02f0a29901
Para respetar las reglas de http://www.php-fig.org/psr/psr-2/ ("There MUST NOT be a hard limit on line length; the soft limit MUST be 120 characters; lines SHOULD be 80 characters or less."), preferimos espaciar con líneas los parámetros de funciones cuya llamada es amplia
9 years ago
Rafa
04c1a62c0f
Vulnerabilidad
...
Se ha detectado que, al recuperar la contraseña, es posible realizar una denegación de servicio, enviando Email de recordatorio de contraseña, tantas veces como el atacante lo quiera, afectado al usuario. Colapsando su bandeja de entrada y el servidor de correo inundándolo de peticiones.
Solución:
Se recomienda aplicar un método anti-automatización, por lo que no es posible que un atacante pueda enviar más de 3 a 5 intentos de recuperación de contraseña en un corto período de tiempo.
La aplicación de un captcha es la técnica más recomendada para evitar que programas automatizados puedan llevar a cabo ataques de fuerza bruta. Un captcha, básicamente, trata de distinguir entre un ser humano y una máquina, ya que este último es mucho más rápido enviando solicitudes para tratar de iniciar sesión o enviar cualquier petición.
Otro método sería bloquear, por un período de tiempo aleatorio, una IP que está enviando una gran cantidad de peticiones de acceso o de recuperación de contraseña. Eso haría que el ataque pueda durar mucho más, por lo que puede cambiar el tiempo necesario para encontrar una sola cadena de caracteres desde días hasta meses o incluso años.
9 years ago
Scrutinizer Auto-Fixer
1c47b10a5e
Scrutinizer Auto-Fixes
...
This commit consists of patches automatically generated for this project on https://scrutinizer-ci.com
9 years ago
Scrutinizer Auto-Fixer
9b4780a691
Scrutinizer Auto-Fixes
...
This commit consists of patches automatically generated for this project on https://scrutinizer-ci.com
9 years ago
jmontoyaa
fab7a58076
Use __DIR__ when calling global.inc.php
...
This is needed for an easy migration to chamilo v2
9 years ago
jmontoyaa
284d08e2e2
Minor - Change message
10 years ago
jmontoyaa
289550f8c6
Adding extldap message see BT#10674
10 years ago
Angel Fernando Quiroz Campos
aec05212b2
Fix sent duplicated messages on Lost Password page - refs BT#10376 #TMI
10 years ago
Yannick Warnier
a740f7ff03
Move user_reset_password and user_reset_password_token_limit settings to database - refs #7794
11 years ago
Julio Montoya
4c0780aa76
Add new reset password option see BT#9897
11 years ago
Julio Montoya
ee3e5b985a
Set login form
11 years ago
Julio Montoya
a893afb1db
Register and lost password tpl added. #10102
11 years ago
Yannick Warnier
cc540ec185
Minor - Fix button style - refs #7539
11 years ago
Yannick Warnier
5ff099376f
Move registration and create_course language files to trad4all - refs #4467
11 years ago
Yannick Warnier
652c6ecf19
Move index language file to trad4all - refs #4467
11 years ago
Julio Montoya
a36aeeb736
UI changes.
11 years ago
Julio Montoya
57eeea7543
Removing require_once already loaded with composer.
11 years ago
Julio Montoya
7333997ce3
Fixing custom lost password to work as classic Chamilo see BT#8680
11 years ago
Julio Montoya
11169305bf
Commenting "require_once '../inc/global.inc.php';" files inside main are parsed byt the LegacyController
12 years ago
Julio Montoya
3995283642
Fixing lost password custom page see BT#8295
12 years ago
aragonc
94984e6b12
merge
12 years ago
Julio Montoya
f4f0ea6397
Removing require_once for "mail.lib.inc.php"
13 years ago
Julio Montoya
4fa28caad7
Updating variable see #3855
14 years ago
Julio Montoya
0d4384e4b7
Removing unused library lost_password.lib.php all code was moved to login.lib.php
14 years ago
Julio Montoya
5186a7750d
Should fix bug that enables inactive users to ask email passwords see #3855
14 years ago
Laurent Opprecht
21683bf5ed
custom pages clean up: remove unnecessary requires
14 years ago
Julio Montoya
6eeaed6806
Should fix bug when resetting password see #4620
14 years ago
Julio Montoya
c96c5d18f0
More readable code
14 years ago
Julio Montoya
b4bd73e93f
Minor - replacing a_button class with btn
14 years ago
Julio Montoya
4768cc9d40
Style changes: Replacing a_button with btn
14 years ago
Julio Montoya
8ad3aed230
More UI fixes
14 years ago
Julio Montoya
9b744b08b5
Fixing SQL queries
14 years ago
Julio Montoya
42f14329fd
Minor - Fixing headers
14 years ago
Yannick Warnier
096b8663dc
Attempt at renaming to ['password_encryption'] for more clarity
14 years ago
Julio Montoya
86054020ff
Minor - Fixing button style
14 years ago
Julio Montoya
1d25f38796
UI fixes in login and forms
14 years ago
Noel Dieschburg
ef4fbd56ab
6521 : generic lost_password custompage
14 years ago