From f8d90e3d80ec798689be5fdf792e6c1401ad748f Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:46:11 +0300 Subject: Security: Throttle login attempts with a per-address, per-account token bucket Nothing stopped a bot from trying passwords against /webadmin as fast as bcrypt would go. A small in-memory limiter (stdlib only, one process) now refuses a login with 429 once an address, or an account, has made ten attempts, and lets one more through every six seconds; keying on both means many addresses guessing one account are throttled too. Refusals are logged. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/i18n/el.go | 1 + 1 file changed, 1 insertion(+) (limited to 'internal/i18n') diff --git a/internal/i18n/el.go b/internal/i18n/el.go index 6a97c83..e2523cb 100644 --- a/internal/i18n/el.go +++ b/internal/i18n/el.go @@ -269,6 +269,7 @@ var el = map[string]string{ "New passwords do not match.": "Οι νέοι κωδικοί δεν ταιριάζουν.", "Password changed.": "Ο κωδικός άλλαξε.", "Wrong username or password.": "Λάθος όνομα χρήστη ή κωδικός.", + "Too many requests. Try again in a minute.": "Πάρα πολλές προσπάθειες. Δοκιμάστε ξανά σε ένα λεπτό.", // ---- layout ---- "Header": "Κεφαλίδα", -- cgit v1.2.3