Project

General

Profile

Actions

Feature #26887

closed

graphql login: count login failures as brute force attempts

Added by Timo Goebel over 5 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
API
Target version:
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

In #26487 a graphql mutation was added that allows users to sign in via username/password. The user is then issued a JWT token. Failed login attempts at this mutation should count as bruteforce attemps as with the login form.


Related issues 2 (0 open2 closed)

Related to Foreman - Feature #26487: add graphql jwt login mutationClosedTimo GoebelActions
Related to Foreman - Bug #28860: Wrong Error Message/Return code getting after exceeding the 'failed_login_attempts_limit'ClosedDominik MatoulekActions
Actions

Also available in: Atom PDF