Variety for login invalid message

Re: Variety for login invalid message

by Daniel Thies -
Number of replies: 1
Picture of Core developers Picture of Plugin developers Picture of Testers
I agree with Davo, not indicating reasons is standard practice not just for security, but privacy reasons as well. However, if you do want to communicate with users that have a valid login, but limited access, you could suspend the user's course enrollments instead of the account.
Average of ratings: Useful (2)
In reply to Daniel Thies

Vs: Re: Variety for login invalid message

by Asko Pesola -
I understand this point, but still cannot buy it. Are you saying that facebook login is not safe because it tells you if email you gave doesn't exist in their database or if you gave wrong password? Or Apple ID login is not safe because it tells you if your Apple ID or password was wrong? The same way every webpage in the internet tells you if your login failed because of wrong email or password making difference with other type of failures. No, I don't buy these security and privacy explanations. In this case Moodle is trying to be overprotective forgetting that webpage should also be user friendly.

At the very minimum Moodle should differentiate three login failures: wrong username or password, suspended user, and lastly if something else went wrong. If we are so concerned about security and privacy of the webpage, we don't even have to tell user which one went wrong, username / email or password. Text "Invalid login" doesn't tell anything about what really happened and it leaves user confused thinking if I just wrote something wrong or what this message means and what happened.

So, since Moodle doesn't do this and there is no plugins to do this, can someone please tell me where I can find language pack for this "Invalid login, please try again" -text. That text doesn't tell anything to anyone and I want to change it to my Moodle webpage to be at least little bit informative.