Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

failed login throttling only throttles unknown users #401

Closed
tobias opened this issue Oct 27, 2015 · 0 comments
Closed

failed login throttling only throttles unknown users #401

tobias opened this issue Oct 27, 2015 · 0 comments

Comments

@tobias
Copy link
Member

tobias commented Oct 27, 2015

We should also throttle bad password attempts against known users to prevent dictionary attacks. I believe that was the intent of 43b1bd7, but on https://github.com/ato/clojars-web/blob/master/src/clojars/web.clj#L86, it only registers a bad attempt if the user is not found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant