Skip to content

Login brute-force / lockout protection #1424

Description

@mbarton

As recommended by Fable 5 security review. We already have the captcha but it would make sense to have a per account cooldown period for failed logins.

It also suggested IP based rate limits and timeouts but I think we should only add them to defend against a specific ongoing attack if it happens

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: mediumMedium Priority Work - No Max Item LimitsecurityAn issue which affects (or could affect) security

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions