Process Restriction

89 Aufrufe Markdown

Process Restriction limits how many times a visitor can repeat a sensitive action, such as a sign-in attempt or a contact form, within a set window, then blocks them until it passes.

Opening the Screen

It opens from Settings › Security. On the tab strip at the top of the page, select the Process Restriction tab: {admin}/settings/security?general=processRestriction

What Is on the Screen

An info banner explains the idea: define how long there must be between certain actions, which stops robots and abusers using a fixed IP address. It cannot stop attempts made through proxies or ever-changing IPs, so the banner recommends BotShield or Captcha Security as an additional measure.

Account Access Sign In, Password Reset, Email Verification, and SMS Verification. Counted in failed attempts.
Public Forms and Lookups Contact Form, New Ticket, Client Comments, Newsletter, Blog Comments, and Domain Name Check. Counted in requests.
Clear Block Records A button at the bottom of the tab that immediately lifts every active block on the installation.

Every row is the same pair of fields

Each action above is one row with two controls: a number of attempts (or requests) and a block duration with its own time unit. Cross either one to zero and the row switches off. It shows an Off badge, and the action is never limited.

Fields

Attempts / Requests How many tries are allowed in the window, shown here for the Sign In row. The same field, under a different name, sits in every other row. Known issue: the four rows in the Account Access group are saved but not yet applied. The rows in the other group do take effect.
Block Duration The window's length and its unit (minutes, hours, days, and so on), shown here for the Sign In row. Once the attempt count is used up inside this window, the visitor is blocked until it elapses.

Tasks

Tighten or loosen a rule

  1. Find the action's row in either group.
  2. Change the attempt/request number and the block duration next to it.
  3. Save. The Off badge disappears as soon as both values are above zero.

Clear every active block

  1. Scroll to the bottom of the tab and click Clear Block Records.
  2. Confirm.
  3. Every block record in the installation is cleared, not only the ones from this tab. Manual IP, e-mail and phone bans go too.

Things to Watch

It does not stop proxies or changing IPs

These rules count by IP address. A visitor who switches IPs, or who uses a proxy or VPN, resets the count every time. Pair a sensitive form with BotShield or Captcha Security for that case.

Clearing block records does not change the rules

The button only resets the counters and lifts the blocks that exist right now. The attempt limits and durations you set stay exactly as they were, so new violations start building up again from zero.

Required Privileges

Opening the tab, saving changes, and clearing block records need SECURITY_SETTINGS.

War das hilfreich?

Vielen Dank für Ihre Rückmeldung!

Brauchen Sie weitere Hilfe?

Unser Support-Team ist rund um die Uhr für Sie da, wenn Sie oben nicht fündig werden.