Details
-
New Feature
-
Resolution: Fixed
-
Minor
-
None
-
None
Description
As mentioned in https://forum.xwiki.org/t/limit-number-of-login-attempts-until-user-gets-blocked/3432 it would be nice to have a feature to limit the number of failed logins in the standard xwiki authenticator. I am thinking of two properties like
login.max.failed.attempts=3
login.failed.timewindow=5 (minutes)
Where a user gets blocked if he fails to login 3 times within 5 minutes.
Attachments
Issue Links
- blocks
-
XWIKI-16532 Add an authentication failure strategy to block user
- Closed
- causes
-
XWIKI-18229 Authentication security administration title is not translatable
- Closed
-
XWIKI-19024 DefaultAuthenticationFailureManager#getMaxTime will fail for time window bigger than 25 days
- Closed
- is related to
-
XWIKI-16762 Add a lifespan to the authentication failures data
- Open
- relates to
-
XWIKI-18133 Cannot login after disabling the authentication security mechanism
- Closed
-
XWIKI-16776 Authentication configuration files are not hidden
- Closed
-
XWIKI-18267 security-authentication-api is using a bad package name.
- Closed
-
XWIKI-16763 Allow to reset an authentication failure record
- Open
-
XWIKI-16539 TestUtils#login should fail by default if the authentication failed
- Closed