POST /login has no rate limiting. An attacker can attempt unlimited password guesses.
Impact
Brute force attacks against the admin account are trivial.
Fix
Add rate limiting middleware to the login POST endpoint. A simple approach: use golang.org/x/time/rate or go-chi/httprate to limit login attempts per IP (e.g. 5 attempts per minute).
## Summary
`POST /login` has no rate limiting. An attacker can attempt unlimited password guesses.
## Impact
Brute force attacks against the admin account are trivial.
## Fix
Add rate limiting middleware to the login POST endpoint. A simple approach: use `golang.org/x/time/rate` or `go-chi/httprate` to limit login attempts per IP (e.g. 5 attempts per minute).
## Location
`internal/server/routes.go` — `/login` route
`internal/middleware/middleware.go` — add rate limit middleware
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
POST /loginhas no rate limiting. An attacker can attempt unlimited password guesses.Impact
Brute force attacks against the admin account are trivial.
Fix
Add rate limiting middleware to the login POST endpoint. A simple approach: use
golang.org/x/time/rateorgo-chi/httprateto limit login attempts per IP (e.g. 5 attempts per minute).Location
internal/server/routes.go—/loginrouteinternal/middleware/middleware.go— add rate limit middleware