Skip to content

fix(auth): rate limit POST /auth/login (IP + email + lockout) - #351

Merged
ShreeChaturvedi merged 1 commit into
mainfrom
fix/344-login-rate-limit
Aug 3, 2026
Merged

ShreeChaturvedi merged 1 commit into
mainfrom
fix/344-login-rate-limit

Conversation

@ShreeChaturvedi

Copy link
Copy Markdown
Owner

Summary

  • Per-IP (30/15m) and per-email (10/15m) rate limits on login.
  • Optional lockout after 8 failures (env-configurable).
  • Unit tests for allow / email limit / lockout paths.

Fixes #344

Add loginRateLimit middleware with configurable windows, optional
lockout after N failures, and focused unit tests. Document defaults
in the middleware header.

Fixes #344
@ShreeChaturvedi
ShreeChaturvedi merged commit 8d1752a into main Aug 3, 2026
@ShreeChaturvedi
ShreeChaturvedi deleted the fix/344-login-rate-limit branch August 3, 2026 21:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(auth): /auth/login has no rate limiting; credential-stuffing vector

1 participant