Skip to content

Lower max_bad_passwords#7757

Merged
Rwolfe-Nava merged 1 commit intomainfrom
lg8705-update-rate-limit-defaults
Feb 6, 2023
Merged

Lower max_bad_passwords#7757
Rwolfe-Nava merged 1 commit intomainfrom
lg8705-update-rate-limit-defaults

Conversation

@Rwolfe-Nava
Copy link
Contributor

changelog: Internal, Attempts Api, Bugfix

🎫 Ticket

Link to the relevant ticket.
LG-8705

🛠 Summary of changes

lower max_bad_passwords for the session_controller to a value that is under the Rack Attack value so that Attempts Api login_rate_limited event is properly logged before a Rack Attack.

This should also make security a bit more strict, and Rack Attack will still be in place to catch attackers if the session_controller rate limit is bypassed.

… is properly logged before a Rack Attack

changelog: Internal, Attempts Api, Bugfix
@Rwolfe-Nava Rwolfe-Nava marked this pull request as ready for review February 6, 2023 15:57
@Rwolfe-Nava Rwolfe-Nava changed the title WIP - Lower max_bad_passwords Lower max_bad_passwords Feb 6, 2023
@Rwolfe-Nava Rwolfe-Nava merged commit f6f39f2 into main Feb 6, 2023
@Rwolfe-Nava Rwolfe-Nava deleted the lg8705-update-rate-limit-defaults branch February 6, 2023 23:36
@aduth aduth mentioned this pull request Feb 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants