Support

Admin Tools

#23375 3.6.2 secret admin url QUICK SETUP

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by Ch3vr0n on Monday, 05 October 2015 15:08 CDT

Ch3vr0n
After updating to 3.6.2 i noticed the new "Quick Setup Assistent" so i checked it out. I noticed it had filled in a secret url paramater automatically. Now according to the documentation listed above, point 1, the admin url should not be accessible without that ?<secret>

yet i can visit site.tld/administrator (note: no ?<secret) just fine. I even double and triple checked this with logging out and logging in. /administrator visible like always. So i logged back in and went back to the quick setup. I noticed the secret had CHANGED!

So to be sure i wasn't going crazy i closed it. Went to <site>administrator/index.php?option=com_admintools&view=quickstart and took a note of the secret parameter: it stated "i9OND0Tj". I pressed F5 to refresh, the secret had changed to "mxaVREh6"

Enable IP workarround also seems to reset itself to yes after i changed it to NO as per recommendation by the wizard (afaik i hadn't even enabled it in 3.6.1 because i know it's not).

I'm guessing the setup assistent isn't working the way it should be

nicholas
Akeeba Staff
Manager
Every time you visit the quick setup the proposed RANDOM secret URL parameter changes. That's the point of it being random. Otherwise all sites would be hackable since the hardcoded parameter would be the same for everyone. If you don't save it it's not applied. If you are already logged in or if you have whitelisted your IP then indeed it has no effect.

Same applies for workarounds. They are evaluated each time you run the wizard. This is by design. If we could tell this value without going through the browser then there would not be an option there, it would just pick the correct value by itself.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Ch3vr0n
But the tooltip nor string (nor tooltip) indicate its a RANDOM generated one. I understand a hardcoded one would be hackable. I just figured that once it generated one and you pressed save, it would be remembered for next time. can this parameter be configured / changed somewhere without the quick setup? or was this intentionally changed from the previous version (i believe upto 3.6.1 you could set and save it on one of the subtabs)

My IP was apparantly whitelisted, i'll remove that because it's "semi-static". Forgot i even had done that.

So if i just want to be able to access the /administrator url without a secret parameter, i just do it the "normal" way? configuring straight from the sub-tabs? Do i understand you correctly?

nicholas
Akeeba Staff
Manager
Whenever you visit the wizard it resets your configuration. That's why you generate a new key every time.

So if i just want to be able to access the /administrator url without a secret parameter, i just do it the "normal" way? configuring straight from the sub-tabs? Do i understand you correctly?


Or you can delete the random secret URL parameter in the quick setup wizard. Both ways work.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Ch3vr0n
Understood, thanks.

case closed :)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!