Exclude system _cli_ user from HasInsecureBackendUsers counts - #55
Open
elaphos wants to merge 1 commit into
Open
Exclude system _cli_ user from HasInsecureBackendUsers counts#55elaphos wants to merge 1 commit into
elaphos wants to merge 1 commit into
Conversation
The TYPO3 core auto-creates a _cli_ backend user (admin=1, random unusable password, no MFA, no email) for CLI/scheduler execution. The totalAdmins, adminsWithoutMfa and noEmail counters included it, so every stock v13/v14 install reported at least one admin without MFA and one user without email, firing the corresponding Zabbix triggers (last()>0) permanently. Exclude CommandLineUserCreation::CLI_USERNAME from those three queries. staleUsers is unaffected as _cli_ never performs an interactive login. Adds a functional test with a dedicated be_users fixture. Closes #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The TYPO3 core auto-creates a cli backend user (admin=1, random unusable password, no MFA, no email) for CLI/scheduler execution. The totalAdmins, adminsWithoutMfa and noEmail counters included it, so every stock v13/v14 install reported at least one admin without MFA and one user without email, firing the corresponding Zabbix triggers (last()>0) permanently.
Exclude CommandLineUserCreation::CLI_USERNAME from those three queries. staleUsers is unaffected as cli never performs an interactive login.
Adds a functional test with a dedicated be_users fixture.
Closes elaphos#1