Prevent admin login from everywhere

More
3 years 9 months ago #114871 by htwsaar
htwsaar created the topic: Prevent admin login from everywhere
I try to secure the actual limesurvey installation.

Our German office for data security wants us to prevent administrative logins from the outside.

.htaccess is not helpful because it just blocks mydomain.tld/admin and not the actual and well known link for login in the role of admin.

Can someone help if there is an easy way by edition the index.php in the main folder, for example?
I would do that chance after every future update.

Someone else had the same problem / idea?

Thank you

Please Log in or Create an account to join the conversation.

More
3 years 9 months ago #115173 by htwsaar
htwsaar replied the topic: Prevent admin login from everywhere
I found a way that fits my requirements.

My solution is made with php. I just need to check the changes after every update.

Please Log in or Create an account to join the conversation.

More
3 years 9 months ago #115179 by holch
holch replied the topic: Prevent admin login from everywhere
Isn't it possible to block the "well known" URL via .htaccess as well?

I'm not a LimeSurvey GmbH member. I answer at the LimeSurvey forum in my spare time. No support via private message.
Some helpful links: Manual (EN) | Question Types | Workarounds

Please Log in or Create an account to join the conversation.

More
3 years 9 months ago #115182 by htwsaar
htwsaar replied the topic: Prevent admin login from everywhere
While we are just allowed to use a few .htaccess directives this would not be a solution for us.

Please Log in or Create an account to join the conversation.

More
2 weeks 5 days ago #173304 by sicoda_limesurvey
sicoda_limesurvey replied the topic: Prevent admin login from everywhere
HI, this question is 3 years old, but would you give us a hint waht you changed in php ?

Please Log in or Create an account to join the conversation.

More
2 weeks 5 days ago #173311 by DenisChenu
DenisChenu replied the topic: Prevent admin login from everywhere
It can not be done in manual.limesurvey.org/Authentication_plu...elopment#beforeLogin ?

Quick solution : set a limesurvey with 2 domain accessible : one with example.intra , other with example.org

And something like : if ($_SERVER != "example.intra") { throw 401; }

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand (or search sondages pro).
An error happen ? Before make a new topic : remind the Debug mode .

Please Log in or Create an account to join the conversation.

More
2 weeks 1 day ago #173430 by htwsaar
htwsaar replied the topic: Prevent admin login from everywhere

sicoda_limesurvey wrote: HI, this question is 3 years old, but would you give us a hint waht you changed in php ?


Here is my simple solution:
This works for large ip ranges. By changing the substring you can identify single IPs.
Private unrouted IP ranges would also work (like '192.168').



# Login into admin GUI only for dedicated IP addresses

# in file /application/controllers/admin/authentication.php



$IPRANGE = substr ($_SERVER,0,7);

switch ($IPRANGE) {
case "XXX.XXX":
break;
case "YYY.YYY":

break;

default:

die ('Admins only area!<br />');

Please Log in or Create an account to join the conversation.

Start now!

Just create your account and start using Limesurvey today.

Register now
Join our Newsletter!