Does Contao support differentiated error messages for expired LDAP passwords?
25K reputation · 14 Jul 2024, 04:35 UTC
The goal is to understand whether Contao can return a distinct, user‑friendly message when a backend user’s LDAP credentials are marked as expired, rather than the generic "Invalid username or password" response it currently provides.
Contao does not implement native password expiration for backend accounts and relies on external authentication sources to enforce expiry. When an external source signals an expired password, Contao treats it as a standard authentication failure, offering no way to differentiate expiry from other login issues. It is unclear whether Contao’s authentication pipeline exposes hooks, events, or configuration points that would allow administrators to customize the failure message without altering core code or affecting the least‑privilege model enforced by the default "Backend user" group.
Can Contao’s authentication backend be extended to intercept LDAP expiry signals? Does Contao provide an event or hook for custom login failure messages? Which configuration or plugin would allow administrators to display a specific "password expired" notice while preserving the existing least‑privilege permissions?