Integrate flood with passwordless login

Created on 10 January 2024, 6 months ago
Updated 31 January 2024, 5 months ago

Problem/Motivation

The sending of emails by the passwordless login rest resource is not limited in any way.
This could enable an attacker to send out an unlimited flood of login emails to a victim, if the victims email address is known.

Proposed resolution


Integrate the flood module, similar to how Drupal Core does it for user logins and in the basic auth module, but with dedicated ip and user limits and windows.

The per-user flood events should also be cleared if the user logs in successfully.

✨ Feature request
Status

Fixed

Version

1.0

Component

Code

Created by

πŸ‡¦πŸ‡ΉAustria chfoidl Salzburg

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.69.0 2024