A07: add rate limiting and lockout to password Login #8

Closed
opened 2026-08-13 09:35:02 +00:00 by nalum · 0 comments
Owner

Login (internal/services/user/login.go:21-51) has no per-IP or per-account throttle, no failed-attempt counter, and no lockout. The bcrypt compare (cost 10) is the only brake, so an online brute-force attack runs at CPU speed. The install is internet-reachable through the HTTPS ingress.

The PIN path already solves this: switchprofile.go:28-31 enforces a 2s minimum gap and a 5-miss lockout per chain. Apply the same pattern to the password path.

Fix

  • Add a per-account failed-attempt counter with lockout or exponential delay.
  • Consider a per-IP throttle for the anonymous surface.
  • Reset counters on successful login, as the PIN path does.

Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

`Login` (`internal/services/user/login.go:21-51`) has no per-IP or per-account throttle, no failed-attempt counter, and no lockout. The bcrypt compare (cost 10) is the only brake, so an online brute-force attack runs at CPU speed. The install is internet-reachable through the HTTPS ingress. The PIN path already solves this: `switchprofile.go:28-31` enforces a 2s minimum gap and a 5-miss lockout per chain. Apply the same pattern to the password path. **Fix** - Add a per-account failed-attempt counter with lockout or exponential delay. - Consider a per-IP throttle for the anonymous surface. - Reset counters on successful login, as the PIN path does. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:46 +00:00
nalum closed this issue 2026-08-13 11:39:57 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#8
No description provided.