From 2ea97f06431c1da6e65fceb1afa77e0e2703e3e3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Felix=20Sp=C3=B6ttel?= <1682504+fspoettel@users.noreply.github.com> Date: Sun, 6 Sep 2020 13:08:44 +0200 Subject: [PATCH] Do not log failed login attempts for MissingToken errors * Due to the way that the /login UI works, this persists at least one failed login each time a user logs into the admin panel. This in turn triggers fail2ban at some point. --- management/daemon.py | 3 --- 1 file changed, 3 deletions(-) diff --git a/management/daemon.py b/management/daemon.py index 3aee9e32..0ff8f2a5 100755 --- a/management/daemon.py +++ b/management/daemon.py @@ -127,9 +127,6 @@ def me(): try: email, privs = auth_service.authenticate(request, env) except totp.MissingTokenError as e: - # Log the failed login - log_failed_login(request) - return json_response({ "status": "missing_token", "reason": str(e),