The admin opens at https://your-site/opensolr-chat/admin, behind a password and, once its keys are saved, a captcha.
Once both reCAPTCHA keys are saved on the Captcha tab, the admin asks you to confirm that you are a person before any of its pages opens while you are signed out, and the sign-in form asks again. Once you are signed in, it does not ask again.
A solved captcha is remembered in that browser, for that IP address, for the hours set on the same tab, 240 by default. Before the keys are saved, the sign-in form has no captcha.
- The password is the one set with the command on The admin password. Spaces before or after a pasted password are ignored.
- Wrong passwords. After five wrong passwords from the same IP address within 15 minutes, signing in is refused until those 15 minutes have passed: Too many failed sign-ins. Please try again in 15 minutes.
- A session lasts until you click Sign out. Closing the browser or leaving the admin unused does not end it: the browser keeps you signed in, for up to 400 days after your last visit. Signing in from another browser does not sign the first one out.
- An expired form. The form expired. Please try again. means the page was loaded before you last signed in, or the browser dropped the admin’s cookies. Reload the page and try again.
Setting a new password signs out every session, in every browser.
- Your API key and your reCAPTCHA secret key are never shown back once saved: their field shows dots and, for a long key, its last four characters. Leave the field empty to keep the saved one.
- Every form of the admin carries a token of your session, and a form sent from another site is refused.
- The session cookie cannot be read by scripts, is not sent with requests that start on other sites, and is marked Secure on HTTPS.
- The admin cannot be shown inside a frame of another site, and asks search engines not to index it.