Skip to content

Flood blocked IPΒΆ

Plugin ID: user:floodblockip

Available since: 1.0.0

Provided tokens

Token Description
[user] The current user.
Alias: current_user
[htmx] Information about the current HTMX request.
[htmx:is_request] Whether the current request was sent by HTMX ("1" or "0").
[htmx:boosted] Whether the current request was boosted by HTMX ("1" or "0").
[htmx:history_restore] Whether the current request is for HTMX history restoration ("1" or "0").
[htmx:target] The identifier of the element the response is targeted at.
[htmx:trigger] The identifier of the element that triggered the request. On Drupal 11 this is the element id, on Drupal 12 and later it is the CSS selector that htmx 4 sends. Prefer "trigger_name", which means the same thing on both.
[htmx:trigger_name] The name attribute of the element that triggered the request, or empty if it has none. This has the same meaning on all supported Drupal versions.
[htmx:source] The CSS selector of the element that triggered the request, for example button[name="first_item"]. Empty on Drupal 11, which does not send this information.
[htmx:request_type] Whether the request targets a full page or a fragment: "full" or "partial". Empty on Drupal 11, which does not send this information.
[htmx:current_url] The URL of the page the request was sent from.
[account] The flooding user entity.
Alias: entity
[event] The event.
[event:machine_name] The machine name of the ECA event.
[session_user] The user account that dispatched the event, regardless if ECA is processing models under a different account. This is only available if ECA is configured to always run under a specific account.

Reacts when a login attempt is blocked by Drupal's flood control due to too many failed attempts from a particular IP address.

This wraps the Drupal core UserEvents::FLOOD_BLOCKED_IP event, which fires when the flood threshold for user.failed_login_ip is exceeded.

Account token may be empty

For IP-based flood blocks, the [account] token may not resolve to a user entity because the flood control only tracks the IP address, not a specific user account.