[wp-trac] [WordPress Trac] #25446: Return HTTP status code 401 upon failed login

WordPress Trac noreply at wordpress.org
Thu Aug 28 14:35:24 UTC 2014


#25446: Return HTTP status code 401 upon failed login
------------------------------------+------------------------------
 Reporter:  raoulbhatia             |       Owner:
     Type:  enhancement             |      Status:  new
 Priority:  normal                  |   Milestone:  Awaiting Review
Component:  Login and Registration  |     Version:  3.6
 Severity:  normal                  |  Resolution:
 Keywords:  has-patch               |     Focuses:
------------------------------------+------------------------------

Comment (by lumpysimon):

 +1 for returning a different status code on failed logins.

 The workaround I'm currently using is to hook into the `wp_login_failed`
 action to generate an entry in the error log, then monitor these with
 fail2ban: http://forum.bytemark.co.uk/t/running-both-fail2ban-and-
 symbiosis-firewall/2017/9

--
Ticket URL: <https://core.trac.wordpress.org/ticket/25446#comment:14>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list