Skip to content

Conversation

@schiessle
Copy link
Member

first check if the user is already logged in and then try to authenticate via apache, this way we suppress wrong audit log messages about failed login attempts

followup on nextcloud/user_saml#254 to suppress the last remaining message

fix #11269

@schiessle schiessle added 3. to review Waiting for reviews bug labels Oct 30, 2018
…cate via apache, this way we suppress wrong audit log messages about failed login attempts

Signed-off-by: Bjoern Schiessle <[email protected]>
@schiessle schiessle force-pushed the suppress-wrong-audit-log-message branch from 44a58a9 to 0efd29f Compare October 30, 2018 21:15
@LukasReschke
Copy link
Member

🙊🙉🙈

@schiessle schiessle added this to the Nextcloud 15 milestone Oct 31, 2018
Copy link
Member

@MorrisJobke MorrisJobke left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Makes sense 👍

@MorrisJobke
Copy link
Member

CI failure is unrelated and is fixed by a hardening by @danxuliu

@rullzer rullzer merged commit 7ba8700 into master Nov 2, 2018
@rullzer rullzer deleted the suppress-wrong-audit-log-message branch November 2, 2018 12:52
@MorrisJobke
Copy link
Member

@schiessle Mind to backport?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SAML SSO generates many “Login attempts” in audit.log

5 participants