You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Limits specifically calls to the 2FA-related actions:
- checking a recovery code
- checking a TOTP value
- checking a Webauthn value
The rate limits were selected to be a balance of usability vs how long
it would take a slow-roll actor to continue trying.
Metrics are emitted for monitoring and alerting purposes.
Refs: #8456
Signed-off-by: Mike Fiedler <[email protected]>
0 commit comments