Configuration

All Icecube settings live at Settings → Icecube in the control panel.

Master Password

The master password is the fallback used to unlock any lock that doesn’t have its own per-lock password. Set it once during setup and share it with the people authorized to unlock content.

The password is hashed before being stored — Icecube never keeps the plaintext. Leave the field blank when editing settings to keep the existing password; enter a new value to replace it.

Admins Bypass

When enabled (the default), admin users automatically skip every lock without being prompted. Disable this if you want admins to go through the unlock flow like everyone else — useful for enforcing the lock as a speed bump even for senior staff.

Element Types

Toggle which element types Icecube can lock. All four are enabled by default:

  • Entries
  • Assets
  • Categories
  • Global sets

Disabling a type prevents you from creating new locks against it, and existing locks on that type stop being enforced.

Unlock TTL

How long an unlock session stays valid after a successful password entry, in minutes. Defaults to 10. The valid range is 1 to 1440 (24 hours).

Shorter TTLs mean editors re-enter the password more often but reduce the window where a walk-away workstation could be used to edit locked content. Longer TTLs are more convenient during long editing sessions.

Brute Force Protection

Icecube limits how many times a user can guess an unlock password. Two settings control it:

  • Failed Attempts Allowed — how many wrong passwords a user may enter for the same item before they’re locked out. Defaults to 5; the valid range is 1 to 100.
  • Lockout Duration — how long that user waits before trying again, in minutes. Defaults to 5; the valid range is 1 to 1440.

Attempts are counted per user, per element, and per action, so one editor mistyping a password never locks out anyone else — and burning through the attempts on one entry doesn’t affect any other. A successful unlock resets the count immediately.

While a user is locked out, even the correct password is refused until the window passes. Attempts made during a lockout aren’t counted, so repeatedly hammering the form can’t extend it.

There’s deliberately no way to switch this off. If you need it effectively unlimited, set the attempt count high rather than looking for a disable toggle.