Ah, there we go, thanks Paul! (and Dale for the email sample)
Will have to check the handling, though it seems that if blocked is still 0, then the Update at line 243 must not have been successful?
I realize that my sysadmin email is not set, which is why I'm not aware of the email.
=====
Dale, can you check:
- If there might be any error logging?
- If the AuditTrail is enabled, does that query exist? Should be around the same date/time of the email.
...and at the risk of having not asked, is there any CRON, trigger, or event schedule established that could be resetting the blocked value?
=====
A basic test of that area appears to be ok for me:
Code:
// error logging added to check the flow
[Sun Nov 25 11:49:53.164714 2018] [php7:notice] [pid 5460:tid 1972] [client ::1:13092] invalid login, referer: http://localhost/webERPgit/index.php
[Sun Nov 25 11:50:11.115807 2018] [php7:notice] [pid 5460:tid 1972] [client ::1:13095] invalid login, referer: http://localhost/webERPgit/index.php
[Sun Nov 25 11:50:21.878688 2018] [php7:notice] [pid 5460:tid 1972] [client ::1:13097] invalid login, referer: http://localhost/webERPgit/index.php
[Sun Nov 25 11:50:27.625743 2018] [php7:notice] [pid 5460:tid 1972] [client ::1:13099] invalid login, referer: http://localhost/webERPgit/index.php
[Sun Nov 25 11:50:38.093704 2018] [php7:notice] [pid 5460:tid 1972] [client ::1:13101] invalid login, referer: http://localhost/webERPgit/index.php
[Sun Nov 25 11:50:38.093704 2018] [php7:notice] [pid 5460:tid 1972] [client ::1:13101] too may failures, setting blocked, referer: http://localhost/webERPgit/index.php
After the 'too many failures', the
blocked was set to 1.
Is there more to know about the demo user's 'restricted privileges'?
What are the demo user settings, so that I can try the same?