Support

Admin Tools

#37292 Administrator secret URL parameter not working on joomla 4????

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
4.1.4
PHP version
n/a
Admin Tools version
latest

Latest post by nicholas on Thursday, 16 June 2022 23:45 CDT

[email protected]

first off I tried to use the search function and either its not working or my browser is glitching but hitting search just bounced me to the top of the page without any visible search box

(firefox up to date on mint)

 

I just transitioned a site to joomla 4 and am setting up waf

after enabling the Administrator secret URL parameter to

https://camoduck.us/green/administrator/index.php?letmein

I went to the standard login page https://camoduck.us/green/administrator/

and it still worked  and I was able to log in from https://camoduck.us/green/administrator/

am I missing something? (also tried it on chrome same issue)

 

in the past I have also used web application firewall but only to get the extra admin password login screen

and I would prefer to dump that and use the admin url instead

 

 

 

nicholas
Akeeba Staff
Manager

Of course it works on Joomla 4. Once you use the secret URL parameter once a flag is set in your session and you are not asked to provide the secret URL parameter for the duration of the session (the session duration is set up in Joomla's Global Configuration page).

Also note the “Browser cookie override for the administrator secret URL parameter” option, by default set to “Enabled, remind to use the full URL”. Once you use the secret URL parameter on a browser and until you explicitly log out from the site there's a cookie set in your browser which tells Admin Tools that you know the secret word. If you try to access the site's administrator without the secret word the cookie will kick in if that setting is anything other than Disabled. If it's just Enabled you will see the admin login page without any other message. The other settings show you a message about it as well.

You DO NOT have to believe me. Open a Private / Incognito browser window and access your site's admin WITHOUT the secret URL parameter. Kicked back to the site's fronted, aren't you?

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

[email protected]

Hi

I tried an incognito window as you suggested and this is how it looked

I also logged out (as I had before) and again the window shown

then I logged in and disabled the cookie setting you mentioned saved it and logged out

and again the same

nicholas
Akeeba Staff
Manager

Please check your server access logs. You will see that on 2022-06-17 04:40 GMT you got an access to /green/administrator/index.php from the IP address 79.107.115.230. It resulted in an HTTP 307 status.  A second later you will see that you got an access to /green from the same IP with a status of 200 OK. That was me testing whether the administrator secret URL parameter works and yes, it does, it kicked me out.

You will see this repeating 3 minutes later. It was me double checking as I am typing this reply. Again, I got kicked out.

Your server access log CANNOT lie. Neither one of us controls it.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!