AI Search
Classic Search
 Search Phrase:
 Search Type:
Advanced search options
 Search in Forums:
 Search in date period:

 Sort Search Results by:

AI Assistant
Notifications
Clear all

[Closed] WpForo not working when auth protected wp-admin folder

6 Posts
3 Users
0 Reactions
2,728 Views
Posts: 17
Topic starter
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@bba01)
Eminent Member
Joined: 9 years ago
[#10341]

Hi!

When I password protect my wp-admin folder with auth (all allowed for wp-admin ajax) I run into trouble.

 

What happens: What happens is that a forum that is shown for everybody (guests) is working but when the users try to enter a forum that's only visible for certain user roles they a required to enter the directory password even though they have access to the forum part with the user role they have.

 

What I expect: Everyone, no one, no matter which user roles they have and which part of the forum they are visiting, should be requested to enter the directory password for wp-admin.

 

How do I solve this as this is an important part of the Wordpress security?

 

With best regards,

 

bb


5 Replies
Posts: 1593
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@anonymous20)
Noble Member
Joined: 10 years ago

"this is an important part of the Wordpress security". Of cource Not. Password protecting anything, doesn't offer any security. It only complicates things. Same with "security by obscurity", hiding things like login and register etc etc.

There are plently of security plugins that protect your Wordpress that work seemlessly with all plugins.

 


2 Replies
(@bba01)
Joined: 9 years ago

Eminent Member
Posts: 17
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian

@anonymous20, please consider being more humble in your responses.

 

I didn't ask about your opinion on my security. I asked what to do when using folder password on wp-admin with wpforo.

 

With best regards,

 

bb

 


(@anonymous20)
Joined: 10 years ago

Noble Member
Posts: 1593
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
Posted by: @bba01

@anonymous20, please consider being more humble in your responses.

 

I didn't ask about your opinion on my security. I asked what to do when using folder password on wp-admin with wpforo.

 

No problem. Good luck.


Sofy
Posts: 5774
 Sofy
Admin
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@sofy)
Support Team
Joined: 8 years ago

Hi @bba01,

Thank you for contacting us.

To tell the truth, this is the first time I've faced with such a question. wpForo doesn't have relation to the WordPress protection system. wpForo uses the WordPress native ajax requests system, which uses /wp-admin/admin-ajax.php file

Please check out the following article by WordPress team. Here you'll find information on how to make your WordPress login system more protected without breaking ajax functionality. 

This is a quote from the article, which explains why it's not recommended password protecting wp-admin:

Password protecting your wp-login.php file (and wp-admin folder) can add an extra layer to your server. Because password protecting wp-admin can break any plugin that uses ajax on the front end, it’s usually sufficient to just protect wp-login.php.

The whole article can be found here: 

https://wordpress.org/support/article/brute-force-attacks/#password-protect-wp-login-php

In this support topic, you'll find a solution on how to password protect all /wp-admin/ folder and at the same time exclude /wp-admin/admin-ajax.php file.

https://wordpress.org/support/topic/how-safe-is-to-allow-access-to-admin-ajax-php/

The solutions are not checked by our team, but we hope it'll be helpful for you. If those solutions don't satisfy you, please contact the WordPress support team to get more correct solutions to solve this issue. 


Posts: 17
Topic starter
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@bba01)
Eminent Member
Joined: 9 years ago

Hi @sofy and thanks for answering!

In my setup I've already allowed admin-ajax.php to be accessed by anyone but I still have the same problem. Are you sure wpforo doesn't use anything else from wp-admin when accessing a forum that only allows a certain forum user role?

One fix is of course to only protect the wp-login.php with an extra layer of security using auth but somehow it feels better to have the whole directory password protected...

With best regards,

 

bb


Share: