security: add IP rate limiting + account lockout on auth endpoints
- Rate limit login (5/min), register (3/hr), refresh (10/min) per IP - Account lockout after 5 consecutive failed logins (15 min cooldown) - Fix stored XSS in admin panel (escapeHtml on all user-controlled data) - All limits configurable via OXICLOUD_RATE_LIMIT_* / OXICLOUD_LOCKOUT_* env vars - Zero new dependencies (uses existing moka crate for in-memory caches) - Includes unit tests for lockout service
This commit is contained in:
@@ -818,6 +818,7 @@ pub struct ApplicationServices {
|
||||
pub struct AuthServices {
|
||||
pub token_service: Arc<dyn crate::application::ports::auth_ports::TokenServicePort>,
|
||||
pub auth_application_service: Arc<AuthApplicationService>,
|
||||
pub login_lockout: Arc<crate::infrastructure::services::login_lockout_service::LoginLockoutService>,
|
||||
}
|
||||
|
||||
/// Global application state for dependency injection
|
||||
|
||||
Reference in New Issue
Block a user