Skip to content

fix(FOUR-33567): block users after failed login attempts and prevent … - #9083

Open
gproly wants to merge 2 commits into
developfrom
bugfix/FOUR-33567
Open

gproly wants to merge 2 commits into
developfrom
bugfix/FOUR-33567

Conversation

@gproly

@gproly gproly commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

…502 on lockout

  • only cache a positive result in Setting::readyToUseSettingsDatabase() so settings are not permanently unavailable in Octane when evaluated before tenant resolution
  • replace gettext _() with Laravel __() in login, 2FA, password expiry, and script executor flows to avoid php-fpm SIGSEGV on macOS (502 Bad Gateway)
  • add regression test for account lockout after too many failed login attempts

https://processmaker.atlassian.net/browse/FOUR-33567

ci:deploy

…502 on lockout

- only cache a positive result in Setting::readyToUseSettingsDatabase() so
  settings are not permanently unavailable in Octane when evaluated before
  tenant resolution
- replace gettext _() with Laravel __() in login, 2FA, password expiry, and
  script executor flows to avoid php-fpm SIGSEGV on macOS (502 Bad Gateway)
- add regression test for account lockout after too many failed login attempts

https://processmaker.atlassian.net/browse/FOUR-33567
@cursor

cursor Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
String translation helper swaps and a feature test; no change to lockout logic beyond how messages are resolved.

Overview
Replaces gettext _() with Laravel __() for user-facing strings in login lockout, 2FA validation, password-expiry redirect, script-executor delete errors, and 2FA email subject. This avoids php-fpm SIGSEGV / 502 on macOS when those paths run during failed login or related auth flows.

Adds testUserIsBlockedAfterTooManyFailedLoginAttempts, which sets password-policies.login_attempts to 3, triggers repeated bad logins, and asserts the locked-account validation message and BLOCKED user status.

Minor non-behavior changes: PHPDoc type hints (e.g. Closure, User, MailMessage), a trailing comma in a 2FA config response array, and whitespace in check2faByGroups.

Reviewed by Cursor Bugbot for commit 05ac884. Bugbot is set up for automated code reviews on this repo. Configure here.

…) with __()

gettext _() causes php-fpm SIGSEGV on macOS when throwing the account
locked response after too many failed login attempts. The user was being
set to BLOCKED in the database, but the UI returned 502 Bad Gateway
instead of the lockout message.

Replace _() with Laravel __() in login, 2FA, password expiry, and script
executor flows. Add a regression test for account lockout after exceeding
the configured login attempt limit.

https://processmaker.atlassian.net/browse/FOUR-33567
@decisions-sonarqube

Copy link
Copy Markdown

@vladyrichter

Copy link
Copy Markdown

QA server K8S was successfully deployed https://tenant-1.ci-900db43097.engk8s.processmaker.net

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants