This may currently open a site up to a brute force attacks

Created on 5 May 2023, over 1 year ago
Updated 16 June 2023, over 1 year ago

Problem/Motivation

The module may currently open a site up to a brute force attacks while attempting to guess the key.

Steps to reproduce

Install the module
Spam the endpoints

Proposed resolution

Limiting the number of failed access checks via the Flood API would be a great way to mitigate that.
Take advantage of the Flood API.
There is a good example of this at:
https://git.drupalcode.org/project/vitals/-/blob/2.x/src/Controller/Vita...

Remaining tasks

Use the Flood API to limit the number of checks

User interface changes

None

API changes

None

Data model changes

None

✨ Feature request
Status

Fixed

Version

1.0

Component

Code

Created by

πŸ‡¬πŸ‡§United Kingdom the_g_bomb

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024