CMS MADE SIMPLE FORGE

Frontend Users

 

[#11996] login problem

avatar
Created By: Jack Skiba (nidus)
Date Submitted: Wed Mar 20 14:02:04 -0400 2019

Assigned To: Robert Campbell (calguy1000)
Version: 2.12.7
CMSMS Version: 2.2.10
Severity: Critical
Resolution: Fixed
State: Open
Summary:
login problem
Detailed Description:
the FEU v.2.12.7 new install sets:

password to be c(64)
but update doesn't change the current c(32)
after the password is salted it is to short and never matches.
therefore login fails

version 2.13
new install sets password to c(128)
and again no change in update.

2.13 is not backwards compatible
it requires salt value in db

forcing confirmation or change of password doesn't create salt value in db.
those users cannot login. 


History

Comments
avatar
Date: 2019-03-25 07:58
Posted By: Rolf (rolf1)

Same issue here:
CMSMS 2.2.10
PHP 7.2.16

After upgrade to FEU version 2.13 users can't login anymore.
Users are marked "Unsafe"

Renew passwords in the Admin doesn't fix the problem...

No PHP errors visible in frontend or admin.
      
avatar
Date: 2019-04-01 11:26
Posted By: Chris Walker (cwalker7007)

Same issue here
      
avatar
Date: 2019-04-06 08:01
Posted By: Robert Campbell (calguy1000)

fixed in svn
      
avatar
Date: 2019-04-15 09:54
Posted By: Jack Skiba (nidus)

great job
Thanks
      
Updates

Updated: 2019-04-06 08:01
resolution_id: => 7