Uploaded image for project: 'Blesta Core'
  1. Blesta Core
  2. CORE-737

Add the ability to ban IP addresses and email addresses.

    Details

    • Type: New Feature
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 3.0.2
    • Fix Version/s: 5.9.0-b1
    • Component/s: Staff Interface
    • Labels:
      None

      Description

      We need the ability for staff to ban certain IP addresses or email addresses. These bans should be honored by..

      1. Login system
      2. Order system
      3. Support system

      I think the feature should be available under Tools, called "Blacklist", and allow you to enter email addresses and IP addresses. Wildcards for email addresses like *@hotmail.com should be allowed, and the CIDR format for IP addresses like 192.168.0.0/24 should be supported as well as individual addresses.

      Update: Allow a reason to be set for each blacklist entry. The order and support plugins won't use this reason in their response, the reasons will be private for staff, but the plugins will set their own reason. In the case of the order system, the same response a rejected/fraud order would see should be used. For the support system, something like "Sorry, we are unable to accept your ticket at the moment."

        Activity

        Show
        admin Paul Phillips added a comment - See http://www.blesta.com/forums/index.php?/topic/900-ban-ip-ban-email-domain/
        Hide
        admin Paul Phillips added a comment -

        For the login system, we block only by IP address, not email address.

        Show
        admin Paul Phillips added a comment - For the login system, we block only by IP address, not email address.
        Hide
        admin Paul Phillips added a comment -

        Increasingly more important to have this.

        Make sure that if the system setting "My installation is behind a proxy or load balancer" is checked, that we evaluate the correct IP address.

        Show
        admin Paul Phillips added a comment - Increasingly more important to have this. Make sure that if the system setting "My installation is behind a proxy or load balancer" is checked, that we evaluate the correct IP address.
        Hide
        jonathan Jonathan Reissmueller added a comment -

        From Paul

        It seems like if they already have an active account they should be able to sign into it. Lets say for example, someone can't sign up because of email (maybe we block free email domains), so we manually create an account for them to bypass and allow access, they should be able to login. The email ban would certainly apply to a client registering an account though, but not to staff creating a client in the client area.

        Show
        jonathan Jonathan Reissmueller added a comment - From Paul It seems like if they already have an active account they should be able to sign into it. Lets say for example, someone can't sign up because of email (maybe we block free email domains), so we manually create an account for them to bypass and allow access, they should be able to login. The email ban would certainly apply to a client registering an account though, but not to staff creating a client in the client area.
        Hide
        admin Paul Phillips added a comment -

        I don't see a field to enter the IP or email to blacklist, there's a Rule, Type, Note field only.. I think a field is missing.

        Show
        admin Paul Phillips added a comment - I don't see a field to enter the IP or email to blacklist, there's a Rule, Type, Note field only.. I think a field is missing.
        Hide
        jonathan Jonathan Reissmueller added a comment -

        Pretty sure "Rule" is the IP or email. I'm assuming it's labeled as such because it handles ip ranges and wildcard email addresses

        Show
        jonathan Jonathan Reissmueller added a comment - Pretty sure "Rule" is the IP or email. I'm assuming it's labeled as such because it handles ip ranges and wildcard email addresses
        Hide
        admin Paul Phillips added a comment -

        Abdy Franco tagging you from my earlier reply, there is still no field to enter IP or email address.

        I don't see a field to enter the IP or email to blacklist, there's a Rule, Type, Note field only.. I think a field is missing.

        Show
        admin Paul Phillips added a comment - Abdy Franco tagging you from my earlier reply, there is still no field to enter IP or email address. I don't see a field to enter the IP or email to blacklist, there's a Rule, Type, Note field only.. I think a field is missing.
        Hide
        admin Paul Phillips added a comment -

        Never mind, "Rule" field is not a rule name but for the actual rule. Dunno why I missed that. Guess we just need CORE-5010

        Show
        admin Paul Phillips added a comment - Never mind, "Rule" field is not a rule name but for the actual rule. Dunno why I missed that. Guess we just need CORE-5010

          People

          • Assignee:
            abdy Abdy Franco
            Reporter:
            admin Paul Phillips
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:
              Fix Release Date:
              15/Dec/23

              Time Tracking

              Estimated:
              Original Estimate - Not Specified
              Not Specified
              Remaining:
              Remaining Estimate - 0 minutes
              0m
              Logged:
              Time Spent - 1 week, 2 hours, 39 minutes
              1w 2h 39m

                Agile