#30767 – Administrator Security

Posted in ‘Akeeba Admin Tools for Joomla!’
This is a public ticket. Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.
Thursday, 10 January 2019 06:07 CST
Hello all, I have just setup Admin tools and have a question. Is it possible to have both Administrator secret URL parameter and Password-protect Administrator active at the same time?

Reason I am asking is that I set them both up but noticed that it was asking for my password when I put in the url:

https://www.test.com/administrator/index.php as well as https://www.test.com/administrator/index.php?test

Is there a way of it only asking for my pw when the secret url parameter?

I hope I explained this properly, thanks!

Jay
Custom Fields
Joomla! version (in x.y.z format)
Latest
PHP version (in x.y.z format)
7.0
Admin Tools version (x.y.z format)
Latest
Edited by MGSW on 2019-01-10 12:07
 
Thursday, 10 January 2019 07:41 CST
Jay,

No, that is the way it is supposed to work. The password is requested the first time you access anything in the /administrator folder in each browser session. This password works at the html server level, so it works before PHP and Joomla! are even loaded.

The secret parameter just becomes part of the back end login URL and makes it much harder for attackers to find your login screen.




Dale L. Brackin


Support Specialist






English: native






Please keep in mind my timezone and cultural differences when reading my replies. Thank you!






Please rate this ticket

Help us improve our support services by rating this ticket from one to five stars, according to how much you are satisfied from the handling of this ticket, one being not satisfied and five being very satisfied.

Support Information

Working hours: Typically we work Monday to Friday, 9am to 7pm Cyprus timezone (EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets, but we cannot respond to them, outside of our working hours.

Support policy: Read the complete support policy which is part of our Terms of Service. We kindly remind our subscribers that they have already explicitly and unconditionally accepted the Terms of Service.

Cookies Notification - Action required

This website uses cookies to provide user authentication and improve your user experience. Please indicate whether you consent to our site placing these cookies on your device. You can change your preference later, from the controls which will be made available to you at the bottom of every page of our site.