From cf22fb1ea39873c323cb4b1238b0fcd6b629174c Mon Sep 17 00:00:00 2001 From: Ilia Ross Date: Mon, 2 Jun 2025 13:16:33 +0300 Subject: [PATCH] Fix Usermin authentication page (once again) This reverts commit 5d586597f5d10e93a3168380bed946e6e75d0291. --- lang/en | 1 - usermin/edit_session.cgi | 3 +-- usermin/lang/en | 2 +- 3 files changed, 2 insertions(+), 4 deletions(-) diff --git a/lang/en b/lang/en index 8fd1fc7a3..287a3cfd7 100644 --- a/lang/en +++ b/lang/en @@ -132,7 +132,6 @@ referer_fix3u=Make sure your browser is configured to send referrer information referer_fix2u=Alternately, you can configure Webmin to allow links from unknown referers by :

WARNING - this has the side effect of opening your system up to reflected XSS attacks and so is not recommended! session_header=Login to Webmin -session_uheader=Login to Usermin session_mesg=You must enter a username and password to login to the Webmin server on $1. session_mesg2=You must enter a username and password to login. session_user=Username diff --git a/usermin/edit_session.cgi b/usermin/edit_session.cgi index 5cb472f57..1269a6e99 100755 --- a/usermin/edit_session.cgi +++ b/usermin/edit_session.cgi @@ -11,10 +11,9 @@ $ver = &get_usermin_version(); &get_usermin_config(\%uconfig); print "$text{'session_desc1'}

\n"; -print "$text{'session_desc2'}

\n"; print ui_form_start("change_session.cgi", "post"); -print ui_table_start($text{'session_uheader'}, undef, 2); +print ui_table_start($text{'session_header'}, undef, 2); # Bad password delay print &ui_table_row($text{'session_ptimeout'}, diff --git a/usermin/lang/en b/usermin/lang/en index f5025cc07..18b5711c0 100644 --- a/usermin/lang/en +++ b/usermin/lang/en @@ -57,8 +57,8 @@ lang_title2=Usermin Language and Locale lang_intro=This page allows you to choose which language Usermin will use for displaying titles, prompts and messages session_title=Authentication +session_header=Authentication and session options session_desc1=When enabled, password timeouts protect your Usermin server from brute-force password cracking attacks by adding a continuously expanding delay between each failed login attempt for the same user. -session_desc2=When session authentication is enabled, each logged in users' session will be tracked by Usermin, making it possible for idle users to be automatically logged out. Be aware that enabling or disabling session authentication may force all users to re-login. session_remember=Offer to remember login permanently? session_hostname=Show hostname on login screen? session_realname=Show real hostname instead of name from URL?