fix(user): lock out repeated failed password logins #29
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!29
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/login-lockout"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Loginallowed unlimited online password guessing — the bcrypt compare was the only brake. This mirrors the PIN chain's proven lockout pattern onto the password path:Per-account (durable, on the User record — 3 new proto fields, scrubbed + not client-settable):
Per-peer (in-memory): token bucket on
Peer().Addr(burst 10, 0.5/s refill), charged only on failures. X-Forwarded-For deliberately not trusted (nothing vets it); behind the ingress this collapses to one shared budget — accepted at household scale, noted in code.golang.org/x/timepromoted indirect → direct.buf breakingclean (additive fields only). 9 new Ginkgo specs;make check,-race, and the integration suite pass.Fixes #8
🤖 Generated with Claude Code
521ac0334366fb969e99