[Toolserver-l] CAPTCHA can be required for logins fromtoolserver hosts

Happy-melon happy-melon at live.com
Mon Jun 21 23:04:04 UTC 2010


"Michael Peel" <email at mikepeel.net> wrote in message 
news:2C5A77A6-51B3-4C29-8374-DA5910555CDB at mikepeel.net...
> Is this something that an en.wp admin can solve, or does it need developer 
> intervention?
>
> Mike

I assume the problem is:

1) Bot gets a bad password, or other problem logging in
2) Bot tries and fails several times to log in, thereby exceeding the login 
throttle
3) subsequent login attempts require a captcha and hence cannot be performed 
through the API
4) there is no method to reset the throttle except by waiting for it to 
expire

What's needed, clearly, is a throttle IP whitelist.  Implementing it more 
cleanly than the Just Another Whitelist In A Global Variable method, is 
another question...

--HM
 





More information about the Toolserver-l mailing list