aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/handlers_auth.go
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:46:11 +0300
committergrm <grm@eyesin.space>2026-09-18 13:46:11 +0300
commitf8d90e3d80ec798689be5fdf792e6c1401ad748f (patch)
tree80e37791696168eb09ccccdec37bfc0f75e4f52d /internal/web/handlers_auth.go
parent90578f02d851ab4e28a066404fbcf4be6a0ed9a7 (diff)
downloadblogspace-f8d90e3d80ec798689be5fdf792e6c1401ad748f.tar.gz
blogspace-f8d90e3d80ec798689be5fdf792e6c1401ad748f.tar.bz2
blogspace-f8d90e3d80ec798689be5fdf792e6c1401ad748f.zip
Security: Throttle login attempts with a per-address, per-account token bucket
Nothing stopped a bot from trying passwords against /webadmin as fast as bcrypt would go. A small in-memory limiter (stdlib only, one process) now refuses a login with 429 once an address, or an account, has made ten attempts, and lets one more through every six seconds; keying on both means many addresses guessing one account are throttled too. Refusals are logged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/handlers_auth.go')
-rw-r--r--internal/web/handlers_auth.go5
1 files changed, 5 insertions, 0 deletions
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go
index 1321b2d..1545a4e 100644
--- a/internal/web/handlers_auth.go
+++ b/internal/web/handlers_auth.go
@@ -52,6 +52,11 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
s.renderStatus(w, r, http.StatusUnauthorized, "auth/login.html",
map[string]any{"error": s.tr(r, "Wrong username or password."), "username": username, "next": next})
}
+ // Both buckets must have a token: one address guessing many accounts and
+ // many addresses guessing one account are throttled alike.
+ if !s.throttle(w, r, s.loginLimit, "ip:"+clientIP(r)) || !s.throttle(w, r, s.loginLimit, "user:"+strings.ToLower(username)) {
+ return
+ }
u, err := s.st.UserByUsername(r.Context(), username)
if err != nil {
if !errors.Is(err, store.ErrNotFound) {