5 Failed Logins requires captcha
I know that you have this implemented for security reasons, however I think your implementation may be flawed unless this is how you expect it to work.
Here's how I see it working
If you fail to login 5 times the site should require you to login with a captcha, however once you successfully login with the captcha it should not require you to use the captcha ever time you login that day. I feel it should reset this.
The way it works on the site.
If you fail 5 login attempts it will require you to fill in a captcha EVERY-TIME you login to the site even after successful logins with the captcha.
Is this how you expect it to work?
|