SIP, Envisionware's PC Reservation, and failed login attempts
Hi all, I've stumbled upon an issue with my library's setup involving Koha 18.11.10 and Envisionware's PC Reservation, but I'm not sure if it's a bug or a misconfiguration on our part. If anyone has any tips or feedback, I'd really appreciate it! We use SIP to authenticate patrons who wish to create a computer session via PC Reservation. We also have the Koha FailedLoginAttempts preference set so that an account is locked after X failed login attempts. But I'm noticing that the borrowers.login_attempts field is increased by 1 each time a user logs on to our public computers even if the login is successful on the first attempt. That is, when I create a computer session successfully, the login_attempts count in the borrowers table is increased regardless. I noticed this after doing maintenance on several computers that required me to log in via PC Reservation. When I went to log in to the staff client later, my account had been locked out. Has anyone else experienced this? Arturo Longoria Web Administrator Texas State Law Library www.sll.texas.gov
That shouldn't be happening on 18.11.10, here is the relevant bug: https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=21997 Kyle --- http://www.kylehall.info ByWater Solutions ( http://bywatersolutions.com ) Meadville Public Library ( http://www.meadvillelibrary.org ) Crawford County Federated Library System ( http://www.ccfls.org ) On Tue, Oct 29, 2019 at 12:26 PM Arturo Longoria < Arturo.Longoria@sll.texas.gov> wrote:
Hi all,
I've stumbled upon an issue with my library's setup involving Koha 18.11.10 and Envisionware's PC Reservation, but I'm not sure if it's a bug or a misconfiguration on our part. If anyone has any tips or feedback, I'd really appreciate it!
We use SIP to authenticate patrons who wish to create a computer session via PC Reservation. We also have the Koha FailedLoginAttempts preference set so that an account is locked after X failed login attempts.
But I'm noticing that the borrowers.login_attempts field is increased by 1 each time a user logs on to our public computers even if the login is successful on the first attempt. That is, when I create a computer session successfully, the login_attempts count in the borrowers table is increased regardless. I noticed this after doing maintenance on several computers that required me to log in via PC Reservation. When I went to log in to the staff client later, my account had been locked out.
Has anyone else experienced this?
Arturo Longoria Web Administrator Texas State Law Library www.sll.texas.gov _______________________________________________ Koha mailing list http://koha-community.org Koha@lists.katipo.co.nz https://lists.katipo.co.nz/mailman/listinfo/koha
Thanks for the link, Kyle! Yes, that’s exactly what’s happening here and what I suspected because PC Reservation does not require the Koha password in order to create a session, so I figured Koha was reacting to that and counting it as a failed login attempt. But yes, despite the note in the bug, I can confirm that is happening on our instance that is using 18.11.10. I tested it this morning several times. From: Kyle Hall <kyle.m.hall@gmail.com> Sent: Tuesday, October 29, 2019 11:44 To: Arturo Longoria <Arturo.Longoria@sll.texas.gov> Cc: koha@lists.katipo.co.nz Subject: Re: [Koha] SIP, Envisionware's PC Reservation, and failed login attempts That shouldn't be happening on 18.11.10, here is the relevant bug: https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=21997 Kyle --- http://www.kylehall.info ByWater Solutions ( http://bywatersolutions.com ) Meadville Public Library ( http://www.meadvillelibrary.org ) Crawford County Federated Library System ( http://www.ccfls.org ) On Tue, Oct 29, 2019 at 12:26 PM Arturo Longoria <Arturo.Longoria@sll.texas.gov<mailto:Arturo.Longoria@sll.texas.gov>> wrote: Hi all, I've stumbled upon an issue with my library's setup involving Koha 18.11.10 and Envisionware's PC Reservation, but I'm not sure if it's a bug or a misconfiguration on our part. If anyone has any tips or feedback, I'd really appreciate it! We use SIP to authenticate patrons who wish to create a computer session via PC Reservation. We also have the Koha FailedLoginAttempts preference set so that an account is locked after X failed login attempts. But I'm noticing that the borrowers.login_attempts field is increased by 1 each time a user logs on to our public computers even if the login is successful on the first attempt. That is, when I create a computer session successfully, the login_attempts count in the borrowers table is increased regardless. I noticed this after doing maintenance on several computers that required me to log in via PC Reservation. When I went to log in to the staff client later, my account had been locked out. Has anyone else experienced this? Arturo Longoria Web Administrator Texas State Law Library www.sll.texas.gov<http://www.sll.texas.gov> _______________________________________________ Koha mailing list http://koha-community.org Koha@lists.katipo.co.nz<mailto:Koha@lists.katipo.co.nz> https://lists.katipo.co.nz/mailman/listinfo/koha
participants (2)
-
Arturo Longoria -
Kyle Hall