I installed AT PRO and filled up the web form of the Quick setup wizard to allow Password-protect Administrator.
When saving I have had only once the browser dialog box open asking for allowed users and password. I don't remember exactly when I mismatched my credentials but, of course, my IP was soon banished and I was treated badly :D
So… I deactivated main.php in /plugins/system/admintools/admintools/ (please note that there are two admintools folder whereas the help page doesn't mention this). When I was in the AT PRO back-end again, I clicked on the "allow my IP" (or the kind) button and the renamed main.php back to its genuine name.
Then I did never encountered the browser dialog box to first log as an authorized user.
When I read further more on this problem, I double checked if the .passwd file was actually created in /administrator folder and the answer is : yes. It contains something like :
notajoomlausernamewithonlyaz09:AkindOFencryptedPAS$$w0rdetc.
and the .htaccess file above includes:
AuthUserFile "/var/www/vhosts/mystie.com/httpdocs/administrator/.htpasswd" AuthName "Restricted Area" AuthType Basic require valid-user RewriteEngine On RewriteRule \.htpasswd$ - [F,L]
So what's wrong ?
I have tried with another browser, the same issue: only Joomla login.
I have read again this page https://www.akeebabackup.com/documentation/troubleshooter/atwafissues.html and deleted the Security Exceptions log. Didn't help. And there is no white list.
I pushed the Purge sessions button, the same issue.
I don't know if AT PRO is secure, but one thing is sure, I'll never be able to hack anything… excepted, maybe, a banana :D
Any idea ? I did my best… (tired) :(
Thank you.