diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:46:11 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:46:11 +0300 |
| commit | f8d90e3d80ec798689be5fdf792e6c1401ad748f (patch) | |
| tree | 80e37791696168eb09ccccdec37bfc0f75e4f52d /internal/web/handlers_auth.go | |
| parent | 90578f02d851ab4e28a066404fbcf4be6a0ed9a7 (diff) | |
| download | blogspace-f8d90e3d80ec798689be5fdf792e6c1401ad748f.tar.gz blogspace-f8d90e3d80ec798689be5fdf792e6c1401ad748f.tar.bz2 blogspace-f8d90e3d80ec798689be5fdf792e6c1401ad748f.zip | |
Security: Throttle login attempts with a per-address, per-account token bucket
Nothing stopped a bot from trying passwords against /webadmin as fast
as bcrypt would go. A small in-memory limiter (stdlib only, one
process) now refuses a login with 429 once an address, or an account,
has made ten attempts, and lets one more through every six seconds;
keying on both means many addresses guessing one account are throttled
too. Refusals are logged.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/handlers_auth.go')
| -rw-r--r-- | internal/web/handlers_auth.go | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go index 1321b2d..1545a4e 100644 --- a/internal/web/handlers_auth.go +++ b/internal/web/handlers_auth.go @@ -52,6 +52,11 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { s.renderStatus(w, r, http.StatusUnauthorized, "auth/login.html", map[string]any{"error": s.tr(r, "Wrong username or password."), "username": username, "next": next}) } + // Both buckets must have a token: one address guessing many accounts and + // many addresses guessing one account are throttled alike. + if !s.throttle(w, r, s.loginLimit, "ip:"+clientIP(r)) || !s.throttle(w, r, s.loginLimit, "user:"+strings.ToLower(username)) { + return + } u, err := s.st.UserByUsername(r.Context(), username) if err != nil { if !errors.Is(err, store.ErrNotFound) { |
