Do not render a different view when user is found but password invalid #87
No reviewers
Labels
No labels
cat
bug
cat
feature
cat
idea
cat
performance
cat
reliability
cat
security
cat
ui
difficulty
high
difficulty
low
difficulty
mid
prio
high
prio
low
prio
mid
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: Deuxfleurs/guichet#87
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "fabientot/guichet:prevent-bruteforce-on-login-form"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
In order to prevent a bruteforce attack, it is a good practice to not render a different view when the user exists but password is invalid.
It prevents an enumeration of existing accounts that could lead to bruteforce attacks
Do not render a different view when user is foundto Do not render a different view when user is found but password invalidc70bd116b6
to0340e6df2f
0340e6df2f
tof3ca42e37b
f3ca42e37b
tod37b92f422
d37b92f422
to8c894a88d9
8c894a88d9
tob319421c1f