Considering we will use converge to handle authentication for multiple applications I feel it only makes sense to add more security features in ACP minimum such as file permission checks and etc. Converge came with no documentation and less alone no values that files should be properly chmod at. I think this leaves a potential security risk for the not so advanced web master. But as well IMO security should be strengthened here cause Converge is more less the vault now.
- File Permissions Check
- Member Failed Logins Log
- Lock Account for "X" mins after "X" failed attempts
- Custom Html page notice when Converge mysql connection fails - Don't know how this can be handled - If the server that converge resides on is down for an hour, hours or whatever we should get some kind of notice. That way the guest can contact me directly if the Converge login/registration is down. Or else months can go by and Will never know any instance of server outage. Maybe provide admin contact info and alternate site address to visit notice on a html error page?
- Send Admin email when user account becomes locked template
- Send member email when account becomes locked template
- Add suspend member option so account is frozen (Only two options currently delete or ban which I may just want to put account on hold for investigation or whatever).
- Send member email when account becomes suspended template
- General Configuration setting - Add metatag, description and keywords fields so that we can better instruct search bot and spiders.
- Ability edit/change member account to admin. Right now you can't pick a member to add as admin, you have to create a new admin creating a new account with new password. Kinda of confusing and awkward when you can simply search for member and change their status from member to admin.
- Add ban this member to the validation, approve, delete menu. For those annoying members who can't take a hint.