htaccess delayed passwd prompt on administrator folder Topic is solved

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9711
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

htaccess delayed passwd prompt on administrator folder

Post by AMurray » Sun Jan 10, 2021 9:42 pm

This is just a general question and observation in my specific experience on my sites(not necessarily a problem):

I have Akeeba Admin Tools installed on my sites, and used it to set up the .htaccess protection on the /administrator folder. I "pin" the tabs for these /administrator URLS for these sites for convenience of access.

I've noticed that as Firefox is starting, it actually loads the joomla admin login pages (as if the htaccess is not actively protecting the folder), but then a few minutes later, the htpasswd prompt pops-up as expected. I would expect the prompt to come up before the page loads but this delay by a minute or so is strange.

* I don't think Joomla or Akeeba Tools is the problem

* I'm not sure if it's a page caching issue

* I don't know if its associated with the way I access the pages e.g. pinned browser tabs rather than clicking bookmark/favourite or direct typing the URL.

Has anyone else observed this same behaviour (the loading of the /administrator login before the htaccess prompts you for the secondary credentials)?

Note: I've only observed this in Firefox so far, not tested in alternative browsers but will do in Edge and Google Chrome when I get a chance. I first wanted to confirm if the observed behaviour above has been experienced by others or if it's "just me".

I'm not sure if this belongs in security (as it may not be a direct Joomla issue); Moderators feel free to move it as appropriate.

Thank you.
Regards - A Murray
General Support Moderator

User avatar
abernyte
Joomla! Virtuoso
Joomla! Virtuoso
Posts: 4189
Joined: Fri May 15, 2009 2:01 pm
Location: Écosse - Scozia - Escocia - Škotija -स्कॉटलैंड

Re: htaccess delayed passwd prompt on administrator folder

Post by abernyte » Mon Jan 11, 2021 10:46 am

Could your browser just be loading your cached Joomla admin login page before the webserver processes the .htpasswd directive?
"Those who expect to reap the blessings of freedom must, like men, undergo the fatigue of supporting it." Thomas Paine

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9711
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: htaccess delayed passwd prompt on administrator folder

Post by AMurray » Mon Jan 11, 2021 9:18 pm

abertnyte wrote:Could your browser just be loading your cached Joomla admin login page....
That makes sense. It's no big concern, eventually the prompt comes up when the server catches up.

Thanks.
Regards - A Murray
General Support Moderator


Locked

Return to “Security in Joomla! 3.x”