aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/ratelimit.go
Commit message (Collapse)AuthorAgeFilesLines
* Security: Throttle login attempts with a per-address, per-account token bucketgrm2026-09-181-0/+87
Nothing stopped a bot from trying passwords against /webadmin as fast as bcrypt would go. A small in-memory limiter (stdlib only, one process) now refuses a login with 429 once an address, or an account, has made ten attempts, and lets one more through every six seconds; keying on both means many addresses guessing one account are throttled too. Refusals are logged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A