Each failed login attempt via basic auth increases the failed login count by 2

XMLWordPrintable

    • 4.02
    • 4
    • Severity 3 - Minor
    • 1

      NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.

      I have a user called "fred" with the password "fred".

      Whenever I try to authenticate as him using basic auth and the wrong password, the Current Failed Login Count increases by 2, not 1.

      With CAPTCHA set to required after 3 failures, this means it is instead requiring CAPTCHA after 2 failures.

      Before the attempt:

      Bad login request: (the credentials are fred:notfred)

      Unauthorised response:

      Value is incorrect:

        1. 1FredBeforeLogin.png
          1FredBeforeLogin.png
          9 kB
        2. 2FredBadLoginRequest.png
          2FredBadLoginRequest.png
          5 kB
        3. 3FredBadLoginResponse.png
          3FredBadLoginResponse.png
          16 kB
        4. 4FredIncorrectLoginCount.png
          4FredIncorrectLoginCount.png
          12 kB

            Assignee:
            Unassigned
            Reporter:
            Penny Wyatt (On Leave to July 2021)
            Votes:
            7 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated: