Skip to content

Conversation

@valorin
Copy link
Contributor

@valorin valorin commented Jun 27, 2025

Adding missing rate limiting to the following routes to make brute-force attacks harder:

  • User Registration
  • Forgot Password
  • Reset Password
  • Password confirmation
  • Password change

@taylorotwell
Copy link
Member

Blocks legit users because it throttles on IP.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants