Magic Login Linkfor WHMCS · Documentation
v2.5.0

Changelog

Everything that changed between releases — from the first passwordless login engine to full observability in v2.5.


v2.5.0 Current

Module Activity Logs & observability

  • New Activity Logs screen: server-side DataTable with global search, severity and event-type filters, severity badges, actor labels and metric cards (total events, failures, admin/user actions).
  • New hsc_magiclink_activity_logs table recording every event: token_requested, token_sent_admin, email_sent, email_failed, login_success, login_failed, token_invalidated, tokens_invalidated, token_deleted, rate_limit_exceeded, user_agent_mismatch, ip_mismatch.
  • Every email send is logged — client requests, admin sends and security alerts record email_sent / email_failed in the Activity Logs.
  • Analytics Dashboard — token counts by status, successful logins with month-over-month trend, security events, throttled attempts, top users, recent activity and a system health panel.
  • Audit table actions — per-row Invalidate (AJAX) and Delete (AJAX with SweetAlert confirmation, no page reload); deleting a record writes a token_deleted entry to the Activity Logs. The Browser & Device column was removed from the audit table.
  • Automatic activity-log pruning via the daily cron (PruneActivityLogsDays, default 60 days).
  • Active menu highlighting on all module admin pages.

v2.4.0

  • Admin configuration page with granular settings: Strict IP Matching, Login Limit Threshold, Security Alerts toggle, Fallback Redirect URL and token pruning retention (PruneLogsDays, default 30 days).
  • Daily cron job now auto-prunes old used/expired/invalidated/failed tokens.

v2.3.0

  • Login Security Alert email — after every successful magic-link login the user receives a notification with account, date & time, IP address and browser/device (EnableLoginSecurityAlert).
  • New Magic Link Security Alert email template with {$user_email}, {$login_time}, {$login_ip}, {$user_agent} merge fields.

v2.2.0

  • Browser & device fingerprint binding — the requester’s User-Agent is stored as a SHA-256 hash (user_agent column) and validated at login (BindUserAgent).

v2.1.0

  • Token status migrated from a legacy integer flag (0/1) to string states — active, used, expired — enabling proper single-use/expiry lifecycle management.

v1.2.0

  • Custom login button — optionally provide your own HTML for the login-page button instead of the built-in one.

v1.1.0

  • Magic Link Request email template moved to the user email type (per-user delivery) and auto-created on activation if missing.

v1.0.0

  • Initial release: passwordless magic-link login with single-use expiring tokens, IP matching, rate limiting, SSO sign-in via CreateSsoToken, automatic token invalidation on password change and email-log suppression.