Skip to content

Commit 377c595

Browse files
committed
Portal login logs
- Mention contact ID in audit log if password is incorrect - Mention in audit logs if invalid email/auth method
1 parent c948ccf commit 377c595

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

portal/login.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -68,13 +68,13 @@
6868
mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Client Login', log_action = 'Success', log_description = 'Client contact $row[contact_email] successfully logged in locally', log_ip = '$ip', log_user_agent = '$user_agent', log_client_id = $row[contact_client_id]");
6969

7070
} else {
71-
mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Client Login', log_action = 'Failed', log_description = 'Failed client portal login attempt using $email', log_ip = '$ip', log_user_agent = '$user_agent'");
71+
mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Client Login', log_action = 'Failed', log_description = 'Failed client portal login attempt using $email (incorrect password for contact ID $row[contact_id])', log_ip = '$ip', log_user_agent = '$user_agent'");
7272
header("HTTP/1.1 401 Unauthorized");
7373
$_SESSION['login_message'] = 'Incorrect username or password.';
7474
}
7575

7676
} else {
77-
mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Client Login', log_action = 'Failed', log_description = 'Failed client portal login attempt using $email', log_ip = '$ip', log_user_agent = '$user_agent'");
77+
mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Client Login', log_action = 'Failed', log_description = 'Failed client portal login attempt using $email (invalid email/not allowed local auth)', log_ip = '$ip', log_user_agent = '$user_agent'");
7878
header("HTTP/1.1 401 Unauthorized");
7979
$_SESSION['login_message'] = 'Incorrect username or password.';
8080
}

0 commit comments

Comments
 (0)