• Resolved deeveearr

    (@deeveearr)


    Following my thread on login queries, I’ve found something that would be of critical importance to any user that is using a ‘hide my login’ type plugin to hide their credentials.

    First I set up a basic forum and changed the layout, and it looks pretty good.

    So I thought I’d now play with the login from a new browser to see how it worked.

    WITHOUT first turning on ‘Anyone Can Register’ in WordPress>General, I attempted to register on the new forum.

    Checking the ‘users’ in WordPress, the new user had been added, so the WpForo software had over-ridden the wordpress settings.

    On checking my email to retrieve login instructions though, there was the full login url INCLUDING the part that took the place of wp-admin – ie my hidden login ie ‘to set your password, please visit mysite.com/my-hidden-login-details’.

    Obviously the forum cannot be used in this state, so how can the hidden login details remain hidden when a new member joins up?

    • This topic was modified 5 years, 11 months ago by deeveearr.
    • This topic was modified 5 years, 11 months ago by deeveearr.
Viewing 9 replies - 1 through 9 (of 9 total)
  • Plugin Author gVectors Team

    (@gvectors-team)

    Hi @deeveearr,
    The email you see is the native WordPress email. This is sent by WordPress user registration functions which is used by wpForo on new user registration. So it contains URL to the native WordPress login page.

    If you want to change the native WordPress login URL to wpForo login page you should enable these two options:
    — “Replace Login Page URL to Forum Login Page URL”
    — “Replace Reset Password Page URL to Forum Reset Password Page URL”
    in Dashboard > Forums > Settings > Features admin page:

    2020-04-19_2354

    Thread Starter deeveearr

    (@deeveearr)

    No good I’m afraid.

    The hidden login field still appears in the email sent from the forum, but only in one place now:

    To set your password, visit the following address:

    mysite.com/hidden-login-details/?action=rp&key=pc2Jcx3EmVx8KhNqIJkS&login=MMsTest

    mysite.com/community/?foro=signin

    How do I get rid of the first line of these addresses that contains the hidden login?

    *edit*

    This also raises concerns if someone wanted to reset their password.

    Would the url complete with hidden login also appear in this case?

    • This reply was modified 5 years, 11 months ago by deeveearr.
    Plugin Author gVectors Team

    (@gvectors-team)

    If you click it you’ll go to wpForo page not to your hidden page. Just click it and see.

    And again, this is not wpForo issue, this is a WordPress issue. You can search for solutions in WordPress support topics or install WordPress Email Editor plugins. You should not try to fix it from wpForo side. wpForo is not the email generator. This is a general WordPress issue.

    As an alternative, you always have a chance to change the user registration type and disable the “Email Confirmation” step by disabling the corresponding “Enable User Registration email confirmation” option in Dashboard > Forums > Settings > Features admin page. So your users can register without email confirmation. The password fields will be displayed on the registration form. They just need to fill the Username, Email, and Password fields and register. Here is the wpForo user registration form “with email confirmation” and “without email confirmation”:

    Thread Starter deeveearr

    (@deeveearr)

    Sorry, posting faster than each other!

    Yes I agree that the link now takes you to the forum login page, but I’m sure that as the hidden login detail is added, someone will notice it and ask what it is.

    I’d prefer to send emails regarding logins, but I’ll also look at the alternative you suggested.

    Thread Starter deeveearr

    (@deeveearr)

    Yes, it works fine now that the emails are not sent – surprised really that it hasn’t been picked up on before.

    I’m guessing that if a user forgets their password though, that the hidden login thing will again be an issue?

    Plugin Author gVectors Team

    (@gvectors-team)

    No, the reset password email will be with the wpForo page URL not with the hidden-path.
    BTW, you can disable back the “Replace Login Page URL to Forum Login Page URL”, but keep enabled the “Replace Reset Password Page URL to Forum Reset Password Page URL” option.

    Thread Starter deeveearr

    (@deeveearr)

    Sure, got you.

    I’ll give the ‘forgotten password’ link a test later just as soon as I’ve added my terms and privacy pages.

    Thread Starter deeveearr

    (@deeveearr)

    Super, the reset password option works fine.

    Thanks for your help this afternoon!

    Plugin Author gVectors Team

    (@gvectors-team)

    You’re welcome.
    BTW. You can change the email templates in Dashboard > Forums > Settings > Emails admin page.

Viewing 9 replies - 1 through 9 (of 9 total)

The topic ‘Critical Login Query’ is closed to new replies.