Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Easy Breadcrumb 2.0.11 — Minor update available for module easy_breadcrumb (2.0.11). Release: Bootstrap 8.x-3.42 — Minor update available for theme bootstrap (8.x-3.42). Release: Editoria11y Accessibility Checker 3.0.10 — Minor update available for module editoria11y (3.0.10). Release: Editoria11y Accessibility Checker 2.2.24 — Minor update available for module editoria11y (2.2.24). Release: Leaflet 10.4.13 — Minor update available for module leaflet (10.4.13). Release: Flag 5.1.1 — Minor update available for module flag (5.1.1). Release: MCP Sentinel 2.33.0 — Minor update available for module mcp_sentinel (2.33.0). Module Revived: Bootstrap 8.x-3.41 — Theme bootstrap updated after 6 months of inactivity (8.x-3.41). Security Coverage: Component Library — Module component_library now has official Drupal security advisory coverage.

Restrict Login Page by IP

75 sites Security covered Drupal 10–11
View on drupal.org

This module restricts access to the user login page, and optionally other user-related pages like registration and password reset, to a pre-defined list of IP addresses. It can also be configured to hide restricted pages by returning a 404 error instead of a 403 forbidden error.

This project lets you restrict access to /user/login page by user IP address.

Features

When allowed IP addresses are set, the /user/login page (including the REST login at /user/login?_format=json) will be accessible only for those addresses and return 403 response for all not-white-listed IP addresses.

In 1.1.x the protection was extended:

  • You can optionally restrict other login-related pages too: user registration, password reset, one-time login links, the login status endpoint and the /user page.
  • You can choose to return a 404 "Not Found" response instead of 403, so the restricted pages appear not to exist at all.

Post-Installation

Visit /admin/config/people/restrict_login_ip to set the list of allowed IP addresses or ranges (in CIDR format) separated by semicolon.

Alternatively, you can set those as $config['restrict_login_ip.settings']['ip_ranges'] in settings.php.

When the variable is empty, the login page is accessible to all IP addresses.

In 1.1.x the same settings page also lets you choose which additional pages to protect and whether to return 404 instead of 403. The module also shows a warning on the status report if another authentication method (such as basic auth) is enabled, since those can bypass the IP check.

Similar projects

This module was created as a replacement for the Restrict Login or Role Access by IP Address module. The differences is that this module:

  1. Checks access to the login page instead of checking it after a user submitted the login form.
  2. Does not log out a user if they changed IP address after login.
  3. Does not block other login methods (like SSO).

Depends on

Dependencies of the latest stable release

  • user Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
7
Tracked since
Oct 2024
Latest release
4 months ago
Releases (12 mo)
4 ▲ from 1
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.0.0 Stable 10–11 May 24, 2026
1.1.0-alpha1 Pre-release 10–11 May 24, 2026
1.1.x-dev Dev 10–11 May 24, 2026
1.0.0-alpha3 Pre-release 10–11 May 24, 2026
1.0.0-alpha2 Pre-release 10–11 Oct 10, 2024
1.0.0-alpha1 Pre-release 10–11 Oct 6, 2024
1.0.x-dev Dev 10–11 Oct 6, 2024