[security] Add rate limiting on login endpoint #37

Open
opened 2026-03-04 12:21:20 +01:00 by clawbot · 0 comments
Collaborator

From Security Audit (#33 comment)

Severity: BLOCKER

Unlimited brute-force attempts possible on the login endpoint.

Suggested fix: Add per-IP rate limiter on /login POST. Consider exponential backoff or account lockout after N failed attempts.

## From Security Audit ([#33 comment](https://git.eeqj.de/sneak/webhooker/issues/33#issuecomment-10915)) **Severity: BLOCKER** Unlimited brute-force attempts possible on the login endpoint. **Suggested fix:** Add per-IP rate limiter on `/login` POST. Consider exponential backoff or account lockout after N failed attempts.
Sign in to join this conversation.
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: sneak/webhooker#37
No description provided.