Difference between revisions of "Security"
From Online Manual
m (1 revision)
Revision as of 13:19, 5 November 2009
The Security page of the Features and Options page of your Category:Administration Panel offers several security related settings that you can configure to meet your needs. Pay close attention to these settings, as a properly secured forum generally should take measures to ensure the safety of itself and its members.
The following are the settings included on this page:
- Do not reveal contact details of members to guests - If selected this option will hide the email addresses and messenger contact details of all members from any guests on your forum
- Allow viewable email addresses - If this option is enabled instead of users email addresses being hidden to normal members and guests they will be publicly viewable on the forum. Enabling this will put your users at greater risk of being victims of spam as a result of email harvesters visiting your forum. Note this setting does not override the user setting for hiding their email address from users. Enabling this setting is not recommended.
- Failed login threshold - Set the number of failed login attempts before directing the user to the password reminder screen.
- Enable error logging - This will log any errors, like a failed login, so you can see what went wrong.
- Include database query in the error log - This will include the full query sent to the database in with any database error. Requires error logging to be turned on. !Note: This will affect the ability to filter the error log by the error message.
- Disable administration security - This disables the additional password check for the administration section. This is not recommended!
- Require reactivation after email change - When this option is checked all members who change their email address in their profile will have to reactivate their account from an email sent to that address
- Require admin approval when member deletes account -
- Enable reporting of personal messages - This option allows your users to report personal messages they receive to the administration team. This may be useful in helping to track down any abuse of the personal messaging system.
- Maximum number of recipients allowed in a personal message - This option allows you to set the maximum amount of recipients allowed in a single personal message sent by a forum member. This may be used to help stop spam abuse of the PM system. Note that users with permission to send newsletters are exempt from this restriction. Set to zero for no limit.
- Post count under which users must enter code when sending personal messages. - This setting will force users to enter a code shown on a verification image each time they are sending a personal message. Only users with a post count below the number set will need to enter the code - this should help combat automated spamming scripts.
- Number of personal messages a user may send in an hour - This will limit the number of personal messages which may be sent by a user in a one hour period. This does not affect admins or moderators.