Ban IP Address in Auth #5232
Replies: 2 comments
-
Update on this, I made this inhouse by just having a collection for ips which have been saved. I make a request to add an ip from our frontend which makes you login to discord first. |
Beta Was this translation helpful? Give feedback.
-
I have 0% experience with PayloadCMS. But would you be able to write this "ip-blacklister" in such a manner that I would be integrate it in my installation as some sort of package, plug-in or extension? Or is it mandatory to weave this feature into the original codebase? Making it more challenging to process future updates of the CMS |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
So currently there is a pretty big security issue, so without 2fa anyone with the url of the admin panel can just bruteforce login into any admin account, if you set a max login requests..it gets worse since anyone can block admins from logging in.
We need a way to ban ip address's on failed logins.. not users
https://discord.com/channels/967097582721572934/1213128284854943774
Beta Was this translation helpful? Give feedback.
All reactions