Skip to content

Built-in mechanism to protect token secrets from brute force #2043

@DWolf-19

Description

@DWolf-19

Request details

Branched from #2026 (comment)

Add a mechanism that will temporarily block auth for host after several unsuccessful attempts by default. Also make it configurable through the configuration file and/or console: ability to change duration of ban, number of failed attempts before host will be banned, etc.

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureNew feature requestsecurityAny issue associated with the general subject of security

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions