Skip to content

v2.14.2

Choose a tag to compare

@github-actions github-actions released this 04 Sep 03:09
· 58 commits to main since this release
v2.14.2: account bans follow the same escalation ladder as IP bans

- Account bans are no longer permanent by default. A risk-control disposition
  now picks its duration from the same escalation ladder IP bans use — first
  offense 10 minutes, then 60, permanent from the third — and each target
  counts its own offenses over the past 90 days.
- Temporary account bans expire on their own: the master node checks every
  minute, restores the account, clears the reason and expiry, invalidates the
  user and token caches, and records an unban_auto event. The loop runs
  independently of the risk-control master switch and the scan interval.
- Manual admin bans are never touched by that loop. Disabling or enabling a
  user by hand always clears the expiry, so a manual ban stays permanent.
- A rule's fixed ban duration now applies to accounts as well as IPs, and the
  duration column is editable for every disposition action, not just "Ban IP".
- Whitelist split is unchanged and now covered by tests: the global whitelist
  exempts everything, while the account-level whitelist only shields the
  account — the source IP is still banned, which is what shared keys need.
- Ban source constants renamed IpBanSource* -> RiskBanSource* (string values
  unchanged) with a new ua_blacklist source for UA-blacklist dispositions.

Upgrade note: existing deployments will see auto-disabled accounts recover
after 10 minutes instead of staying disabled. Set "permanent ban from offense
N" to 1 to keep the old behaviour. Accounts already permanently disabled carry
no expiry and are unaffected.