From e9ea9ad9628182292e850cacdb496a3da38a63bd Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 7 Oct 2026 15:56:24 +0000 Subject: [PATCH 1/2] Hint at automatic cleanup in the blocklist and log views (#214) The blocked IPs (database) list now says whether expired blocks are deleted automatically ("Prune old attempts") and links to the settings. The log view explains that the log file is rotated at 5 MB and where the previous generation is kept. Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01LRuU3DmommJbXWgh5sjoRf --- README.md | 3 +++ admin/language/de-DE/de-DE.com_bfstop.ini | 3 +++ admin/language/en-GB/en-GB.com_bfstop.ini | 3 +++ admin/src/View/Blocklist/HtmlView.php | 1 + admin/src/View/Log/HtmlView.php | 3 +++ admin/tmpl/blocklist/default.php | 7 +++++++ admin/tmpl/log/default.php | 6 ++++++ 7 files changed, 26 insertions(+) diff --git a/README.md b/README.md index 9daf481..5c209a7 100644 --- a/README.md +++ b/README.md @@ -33,6 +33,9 @@ For any further questions, don't hesitate to contact me under bfstop@bfroehler.i - Sending the test email needs the permission to change the settings, and the .htaccess and GeoIP database path settings are validated. - Subnets with a prefix length like `1e1` or `0x8` are no longer accepted. +- The "Blocked IPs (database)" list now shows whether expired blocks are deleted + automatically ("Prune old attempts" setting), and the log view explains that + the log file is rotated at 5 MB. ## 2.0.0: Joomla 5/6 migration diff --git a/admin/language/de-DE/de-DE.com_bfstop.ini b/admin/language/de-DE/de-DE.com_bfstop.ini index 130e64e..75543b0 100644 --- a/admin/language/de-DE/de-DE.com_bfstop.ini +++ b/admin/language/de-DE/de-DE.com_bfstop.ini @@ -83,6 +83,9 @@ COM_BFSTOP_YOUR_IP_IS="Deine IP-Adresse aus der Sicht von BFStop ist %s." COM_BFSTOP_INSTALL_HINT="Bitte sicherstellen, dass BFStop aktiviert und richtig konfiguriert ist! Gehe zur Plugin-Übersicht, klicke auf den Eintrag 'System - Brute Force Stop' (du kannst auch danach oder Teilen des Namens suchen, um es in der langen Liste schneller zu finden), dann setze das Plugin auf 'Aktiviert' - gehe dann zur Einstellungen-Ansicht der Komponente, um es nach deinen Bedürfnissen zu konfigurieren!" COM_BFSTOP_FAILEDLOGIN_AUTOPURGE_ENABLED="Fehlgeschlagene Login-Versuche, die älter als %d Wochen sind, werden automatisch gelöscht. Dies kann über die Einstellung 'Löschen alter Einträge' im Reiter 'Advanced' der Einstellungen geändert werden." COM_BFSTOP_FAILEDLOGIN_AUTOPURGE_DISABLED="Alte fehlgeschlagene Login-Versuche werden derzeit nicht automatisch gelöscht. Um das zu aktivieren, 'Löschen alter Einträge' im Reiter 'Advanced' der Einstellungen setzen, oder mit dem Button 'Alte Einträge löschen' manuell aufräumen." +COM_BFSTOP_BLOCKLIST_AUTOPURGE_ENABLED="Abgelaufene Sperren (und ihre Entsperr-Einträge), die vor mehr als %d Wochen geendet haben, werden automatisch gelöscht. Dies kann über die Einstellung 'Löschen alter Einträge' im Reiter 'Advanced' der Einstellungen geändert werden. Permanente Sperren werden nie automatisch gelöscht." +COM_BFSTOP_BLOCKLIST_AUTOPURGE_DISABLED="Abgelaufene Sperren werden derzeit nicht automatisch gelöscht. Um das zu aktivieren, 'Löschen alter Einträge' im Reiter 'Advanced' der Einstellungen setzen. Permanente Sperren werden nie automatisch gelöscht." +COM_BFSTOP_LOG_ROTATION_INFO="Die Logdatei wird automatisch rotiert, sobald sie %1$d MB überschreitet: das bisherige Log bleibt als %2$s im Joomla-Log-Verzeichnis erhalten (und ersetzt ein älteres) und wird hier nicht angezeigt. Wie viel protokolliert wird, hängt von der Einstellung 'Logging' in den Einstellungen ab." COM_BFSTOP_FAILEDLOGIN_PURGE_BUTTON="Alte Einträge löschen" COM_BFSTOP_FAILEDLOGIN_PURGE_TITLE="Alte fehlgeschlagene Login-Versuche löschen" COM_BFSTOP_FAILEDLOGIN_PURGE_DESC="Alle fehlgeschlagenen Login-Versuche, die älter als die angegebene Anzahl an Tagen sind, werden endgültig gelöscht. Dies kann nicht rückgängig gemacht werden. Sperren sind davon nicht betroffen." diff --git a/admin/language/en-GB/en-GB.com_bfstop.ini b/admin/language/en-GB/en-GB.com_bfstop.ini index b147ad9..893e6e6 100644 --- a/admin/language/en-GB/en-GB.com_bfstop.ini +++ b/admin/language/en-GB/en-GB.com_bfstop.ini @@ -135,6 +135,9 @@ COM_BFSTOP_SETTINGS_RISK_MIN_BLOCK_NUMBER_LABEL="Minimum Allowed Attempts" COM_BFSTOP_SETTINGS_RISK_MIN_BLOCK_NUMBER_DESC="A hard floor on the risk-adjusted number of allowed failed attempts, so an extreme risk score can never reduce it to zero (or below) and effectively block on the very first attempt." COM_BFSTOP_FAILEDLOGIN_AUTOPURGE_ENABLED="Failed login entries older than %d weeks are deleted automatically. You can change this via the 'Prune old attempts' setting in the 'Advanced' tab of the Settings." COM_BFSTOP_FAILEDLOGIN_AUTOPURGE_DISABLED="Old failed login entries are currently not deleted automatically. To enable this, set 'Prune old attempts' in the 'Advanced' tab of the Settings, or use the 'Delete Old Entries' button to clean up manually." +COM_BFSTOP_BLOCKLIST_AUTOPURGE_ENABLED="Expired blocks (and their unblock records) which ended more than %d weeks ago are deleted automatically. You can change this via the 'Prune old attempts' setting in the 'Advanced' tab of the Settings. Permanent blocks are never deleted automatically." +COM_BFSTOP_BLOCKLIST_AUTOPURGE_DISABLED="Expired blocks are currently not deleted automatically. To enable this, set 'Prune old attempts' in the 'Advanced' tab of the Settings. Permanent blocks are never deleted automatically." +COM_BFSTOP_LOG_ROTATION_INFO="The log file is rotated automatically once it exceeds %1$d MB: the previous log is kept as %2$s in the Joomla log folder (replacing an older one) and is not shown here. How much is logged depends on the 'Logging' setting in the Settings." COM_BFSTOP_FAILEDLOGIN_PURGE_BUTTON="Delete Old Entries" COM_BFSTOP_FAILEDLOGIN_PURGE_TITLE="Delete Old Failed Login Entries" COM_BFSTOP_FAILEDLOGIN_PURGE_DESC="All failed login entries older than the given number of days will be permanently deleted. This cannot be undone. Blocks are not affected." diff --git a/admin/src/View/Blocklist/HtmlView.php b/admin/src/View/Blocklist/HtmlView.php index c207ebe..0c3b55b 100644 --- a/admin/src/View/Blocklist/HtmlView.php +++ b/admin/src/View/Blocklist/HtmlView.php @@ -29,6 +29,7 @@ function display($tpl = null) // with .htaccess blocking, blocked requests never reach Joomla, // so attempts can't be counted $this->attemptsTracked = ParamHelper::get('blockMode', 'params', 'full') !== 'htaccess'; + $this->autoPurgeWeeks = (int) ParamHelper::get('deleteOld', 'params', 0); $this->addToolBar(); parent::display($tpl); } diff --git a/admin/src/View/Log/HtmlView.php b/admin/src/View/Log/HtmlView.php index 588e718..39a1165 100644 --- a/admin/src/View/Log/HtmlView.php +++ b/admin/src/View/Log/HtmlView.php @@ -11,6 +11,7 @@ defined('_JEXEC') or die; use Codeling\Component\Bfstop\Administrator\Helper\ToolbarHelper as BfstopToolbarHelper; +use Codeling\Plugin\System\Bfstop\Helper\LoggerHelper; use Joomla\CMS\Language\Text; use Joomla\CMS\MVC\View\HtmlView as BaseHtmlView; use Joomla\CMS\Toolbar\ToolbarHelper; @@ -24,6 +25,8 @@ function display($tpl = null) $state = $this->get('State'); $this->sortColumn = $state->get('list.ordering'); $this->sortDirection = $state->get('list.direction'); + $this->maxLogSizeMb = intdiv(LoggerHelper::MaxLogFileBytes, 1048576); + $this->previousLogFile = str_replace('.log.php', '.1.log.php', LoggerHelper::LogFile); $this->addToolBar(); parent::display($tpl); } diff --git a/admin/tmpl/blocklist/default.php b/admin/tmpl/blocklist/default.php index e68de3e..72dfbcb 100644 --- a/admin/tmpl/blocklist/default.php +++ b/admin/tmpl/blocklist/default.php @@ -9,8 +9,15 @@ use Joomla\CMS\HTML\HTMLHelper; use Joomla\CMS\Language\Text; +use Joomla\CMS\Router\Route; +$settingsUrl = Route::_('index.php?option=com_bfstop&view=settings', false); ?> +
+ autoPurgeWeeks > 0) + ? Text::sprintf('COM_BFSTOP_BLOCKLIST_AUTOPURGE_ENABLED', $this->autoPurgeWeeks, $settingsUrl) + : Text::sprintf('COM_BFSTOP_BLOCKLIST_AUTOPURGE_DISABLED', $settingsUrl); ?> +
diff --git a/admin/tmpl/log/default.php b/admin/tmpl/log/default.php index d68224b..adf7820 100644 --- a/admin/tmpl/log/default.php +++ b/admin/tmpl/log/default.php @@ -8,8 +8,14 @@ defined('_JEXEC') or die; use Joomla\CMS\HTML\HTMLHelper; +use Joomla\CMS\Language\Text; +use Joomla\CMS\Router\Route; +$settingsUrl = Route::_('index.php?option=com_bfstop&view=settings', false); ?> +
+ maxLogSizeMb, $this->escape($this->previousLogFile), $settingsUrl); ?> +
From 96e85658fe22696c640acb77ddf3152280455fc8 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 7 Oct 2026 16:06:13 +0000 Subject: [PATCH 2/2] Mention the username limit in the username statistics view (#214) Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01LRuU3DmommJbXWgh5sjoRf --- README.md | 3 ++- admin/language/de-DE/de-DE.com_bfstop.ini | 1 + admin/language/en-GB/en-GB.com_bfstop.ini | 1 + admin/src/View/Usernamestats/HtmlView.php | 2 ++ admin/tmpl/usernamestats/default.php | 1 + 5 files changed, 7 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 471656c..8994d48 100644 --- a/README.md +++ b/README.md @@ -34,7 +34,8 @@ For any further questions, don't hesitate to contact me under bfstop@bfroehler.i .htaccess and GeoIP database path settings are validated. - Subnets with a prefix length like `1e1` or `0x8` are no longer accepted. - The "Blocked IPs (database)" list now shows whether expired blocks are deleted - automatically ("Prune old attempts" setting). + automatically ("Prune old attempts" setting), and the username statistics view says + that the table is limited to 10,000 usernames. ## 2.0.0: Joomla 5/6 migration diff --git a/admin/language/de-DE/de-DE.com_bfstop.ini b/admin/language/de-DE/de-DE.com_bfstop.ini index e02111c..35a4580 100644 --- a/admin/language/de-DE/de-DE.com_bfstop.ini +++ b/admin/language/de-DE/de-DE.com_bfstop.ini @@ -101,6 +101,7 @@ COM_BFSTOP_HEADING_RANK="#" COM_BFSTOP_HEADING_FAILED_ATTEMPTS="Fehlgeschlagene Logins" COM_BFSTOP_HEADING_FIRST_ATTEMPT="Erster Versuch" COM_BFSTOP_USERNAMESTATS_INFO="Die bei fehlgeschlagenen Login-Versuchen verwendeten Benutzernamen, und wie oft jeder davon verwendet wurde. Diese Statistik wird unabhängig von den fehlgeschlagenen Login-Versuchen geführt und ist daher nicht betroffen, wenn alte fehlgeschlagene Login-Versuche gelöscht werden; sie beginnt erst mit der Installation von (bzw. dem Update auf) BFStop 2.0.0, ausgehend von den zu diesem Zeitpunkt vorhandenen fehlgeschlagenen Login-Versuchen. Ein Klick auf einen Benutzernamen zeigt die dafür noch gespeicherten fehlgeschlagenen Login-Versuche." +COM_BFSTOP_USERNAMESTATS_AUTOTRIM="Es werden höchstens %d Benutzernamen gespeichert: darüber hinaus werden automatisch (einmal täglich) die Benutzernamen mit den wenigsten Versuchen gelöscht. Dieses Limit kann nicht geändert werden." COM_BFSTOP_USERNAMESTATS_EXISTING_ACCOUNT="Existierendes Konto" COM_BFSTOP_USERNAMESTATS_EXISTING_ACCOUNT_DESC="Auf dieser Seite existiert ein Benutzerkonto mit diesem Benutzernamen." COM_BFSTOP_USERNAMESTATS_PURGE_BUTTON="Veraltete Benutzernamen löschen" diff --git a/admin/language/en-GB/en-GB.com_bfstop.ini b/admin/language/en-GB/en-GB.com_bfstop.ini index 5ff8a70..e9b25bd 100644 --- a/admin/language/en-GB/en-GB.com_bfstop.ini +++ b/admin/language/en-GB/en-GB.com_bfstop.ini @@ -153,6 +153,7 @@ COM_BFSTOP_HEADING_RANK="#" COM_BFSTOP_HEADING_FAILED_ATTEMPTS="Failed logins" COM_BFSTOP_HEADING_FIRST_ATTEMPT="First attempt" COM_BFSTOP_USERNAMESTATS_INFO="The usernames used in failed login attempts, and how often each was used. These statistics are kept independently of the failed login entries, so they are not affected when old failed login entries are deleted; they only start with the installation of (or update to) BFStop 2.0.0, seeded from the failed login entries which existed at that time. Click a username to see its failed login entries that are still stored." +COM_BFSTOP_USERNAMESTATS_AUTOTRIM="At most %d usernames are kept: beyond that, the usernames with the fewest attempts are deleted automatically (once a day). This limit can't be changed." COM_BFSTOP_USERNAMESTATS_EXISTING_ACCOUNT="Existing account" COM_BFSTOP_USERNAMESTATS_EXISTING_ACCOUNT_DESC="A user account with this username exists on this site." COM_BFSTOP_USERNAMESTATS_PURGE_BUTTON="Delete Stale Usernames" diff --git a/admin/src/View/Usernamestats/HtmlView.php b/admin/src/View/Usernamestats/HtmlView.php index 6d1f7bd..8bedde9 100644 --- a/admin/src/View/Usernamestats/HtmlView.php +++ b/admin/src/View/Usernamestats/HtmlView.php @@ -11,6 +11,7 @@ defined('_JEXEC') or die; use Codeling\Component\Bfstop\Administrator\Helper\ToolbarHelper as BfstopToolbarHelper; +use Codeling\Plugin\System\Bfstop\Helper\DatabaseHelper; use Joomla\CMS\Factory; use Joomla\CMS\Language\Text; use Joomla\CMS\MVC\View\HtmlView as BaseHtmlView; @@ -27,6 +28,7 @@ function display($tpl = null) $this->sortColumn = $state->get('list.ordering'); $this->sortDirection = $state->get('list.direction'); $this->maxAttempts = $this->get('MaxAttempts'); + $this->maxUsernames = DatabaseHelper::$USERNAME_STATS_MAX_ROWS; $this->canPurge = Factory::getApplication()->getIdentity()->authorise('core.delete', 'com_bfstop'); if ($this->canPurge) { diff --git a/admin/tmpl/usernamestats/default.php b/admin/tmpl/usernamestats/default.php index 4f3e73b..a374eab 100644 --- a/admin/tmpl/usernamestats/default.php +++ b/admin/tmpl/usernamestats/default.php @@ -14,6 +14,7 @@ ?>
+ maxUsernames); ?>