Knowledge Base · Citizens and Compliance

Protected Pages, Admin Logins, API and Form Protection

You open certain sections of the site only to authorized people, monitor logins to site admin, and protect your APIs and forms against abuse.

Protected pages

You can open the whole site, or sections such as staff, tender and council documents, only to authorized people. No change to your site is needed.

  • Shared password: one password for a group such as contractors or board members. It must be at least 8 characters long. NetSSL does not store the password. It keeps only a hash to verify it. The password is shown once when you save it. When the password changes, everyone is signed out.
  • Email code: a 6-digit code is sent only to authorized addresses. A record of who signed in is kept for 1 year.

Ready-made path templates are available: whole site, staff pages, tender and council documents, and test site. *.pdf covers all PDFs. You list the paths that stay public separately (for example /robots.txt). Visitors on networks such as your organization's building are not asked for a password. Protected pages do not appear in search engines. You can define up to 10 protected areas per site.

Protected pages: protected areas and sign-in methods

The password page as the visitor sees it


Site admin login alerts

NetSSL sees successful logins to WordPress, Joomla, Drupal or your own admin page. The username and password in the form are not read or stored. You choose when you are notified:

Option When does it alert you?
Login from a new network or country (recommended) It learns the known networks during the first 3 days. After that, it alerts you when a login comes from a new network or country.
Only logins from abroad For teams that work over mobile connections
Every login At most once every 6 hours for the same IP

The last 100 successful logins are kept for 1 year. Networks used for a login in the last 180 days count as known networks.

Alert on a phone: a login to site admin from a new location

💡
Admin panel lock

To close your admin pages completely, turn on the Admin panel lock rule on the Security page. The pages then open only from the organization's network or with an email code.


API protection

You add rules with ready-made templates for your mobile app, e-municipality integration, WordPress REST or GraphQL addresses:

  • Request limit: by default, 120 requests per minute per IP. A client that goes over it gets a 429 response. An IP that goes over 5 times the limit is banned.
  • Allowed methods: GET, POST, PUT, PATCH and DELETE. Other methods get 405.
  • You can also set a maximum body size and a required Authorization header. A request without the header gets 401.
  • JSON only: if a POST, PUT or PATCH body is not JSON, the response is 415.
  • Allowed origin sites (CORS): browser requests from other sites get 403. Requests from mobile apps and servers are not affected.
  • Test mode: the rule does not block anything. It only counts.

API paths are exempt from the browser verification. A client that breaks a rule gets a clear JSON error response.


Form spam protection

Betting, gambling, adult and advertising messages sent to contact, complaint, application and comment forms are stopped. No "I'm not a robot" box is needed. Form contents are not stored. Only the reason a submission was counted as spam is recorded.

  • Spam reasons include direct submission without a browser, many links, betting and advertising words, the same text repeated, text mostly in a foreign alphabet and words you add yourself (up to 50).
  • With Block (recommended), the visitor sees a page that explains the reason, with an appeal button. With Log only, the submission goes through.
  • Admin pages and logged-in WordPress/Joomla users are not checked.

Form spam protection: reasons and the last 30 days


Frequently asked questions

Do we need to create user accounts for protected pages?

No. A shared password or an authorized email address is enough.

Will API protection break our mobile app?

Run the rule in test mode first. You will see which requests would be caught, without blocking them.