Features
Everything the module does — grouped by area. Every item below is recorded in the module’s Activity Logs audit trail.
Passwordless login
- Login page button — a “Magic Login Link” button is injected automatically into the client-area login page (or supply your own custom button HTML). Clicking it opens a modal where the visitor enters their email address.
- Single-use, expiring tokens — every magic link works exactly once and expires after the configured number of hours (default 24;
0= never expires). - Native SSO sign-in — clicking the link logs the user in through WHMCS’
CreateSsoTokenAPI and redirects to a configurable destination (default/clientarea.php). - Account-enumeration safe — the request form always shows the same generic success response whether or not the email exists.
Security engine
- Strict IP matching — require the login to come from the same IP address that requested the link.
- Browser/device fingerprint binding — the requester’s User-Agent is stored as a SHA-256 hash and must match at login.
- Consecutive login limit — cap how many times a single token can be used in sequence; the counter resets when the user logs in with their normal password.
- Rate limiting & cooldown — per-IP and per-email request throttling with a configurable decay window.
- Automatic token invalidation — all active tokens are expired when the client or user changes their password.
- Login security alert email — after every magic-link login the user receives a notification with the account, date & time, IP address and browser/device used (toggleable).
- Sensitive email suppression — the
EmailPreLoghook stops the magic-link email (which contains the login URL) from being stored in WHMCS’ email logs.
Admin tools
- Send / generate from the admin area — a Send Magic Link action link on the Client Summary page and in the Users & Permissions dropdown of the client users table: send the email instantly or generate a copy-paste URL.
- Analytics Dashboard — token counts by status, lifetime logins with month-over-month trend, security event counts, throttled attempts, top users, recent activity feed and a system health panel.
- Audit table actions — invalidate an active token or permanently delete an audit record straight from the Dashboard, with SweetAlert confirmation and AJAX table reload.
- Activity Logs screen — server-side DataTable with global search, severity and event-type filters, severity badges, actor labels (User / Admin / System) and a per-row AJAX delete.
Email integration
- Two ready-made email templates created on activation: Magic Link Request and Magic Link Security Alert.
- Custom merge fields registered in WHMCS’ email template editor:
{$login_link},{$login_url},{$expire_time}(request) and{$login_ip},{$login_time},{$user_agent}(security alert).
Housekeeping
- Daily cron pruning — old used/expired/invalidated/failed tokens and old activity log rows are removed automatically after the configured retention days.
- Clean deactivation — tables and data are only removed when the Delete Module Database option is enabled.
Every event is audited
Each of the following event types appears in the Activity Logs with a severity level, the acting user or admin, IP address and description:
| Event type | Severity | When it fires |
|---|---|---|
token_requested | info | A client requested a magic link from the login modal. |
token_sent_admin | info | An admin generated a magic link for a client user. |
email_sent | success / info | Any magic-link or security-alert email dispatched successfully. |
email_failed | danger | An email dispatch failed or threw an exception. |
login_success | success | A user signed in via a magic link. |
login_failed | danger | Login rejected (used/expired token, or login limit exceeded). |
ip_mismatch | danger | Login came from a different IP than the request. |
user_agent_mismatch | danger | Login came from a different browser/device fingerprint. |
rate_limit_exceeded | warning | A link request was throttled by IP or email rate limiting. |
token_invalidated | warning | An admin manually invalidated an active token. |
tokens_invalidated | warning | All active tokens expired (e.g. after a password change). |
token_deleted | warning | An admin permanently deleted an audit record. |