forked from 0xWheatyz/SPARC
Security: add rate limiting to /auth/login and /auth/register endpoints #276
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
/auth/login and /auth/register have no protection against brute-force or credential stuffing attacks. An attacker can make unlimited login attempts with no throttling.
Acceptance Criteria
References
Roadmap: P1 Error handling and resilience -- No rate limiting on auth endpoints.