security: add IP rate limiting + account lockout on auth endpoints

- Rate limit login (5/min), register (3/hr), refresh (10/min) per IP
- Account lockout after 5 consecutive failed logins (15 min cooldown)
- Fix stored XSS in admin panel (escapeHtml on all user-controlled data)
- All limits configurable via OXICLOUD_RATE_LIMIT_* / OXICLOUD_LOCKOUT_* env vars
- Zero new dependencies (uses existing moka crate for in-memory caches)
- Includes unit tests for lockout service
This commit is contained in:
Dionisio
2026-03-03 01:44:39 +01:00
parent d2c08d31ba
commit 1df52fd702
11 changed files with 558 additions and 17 deletions
+15
View File
@@ -68,8 +68,23 @@ pub async fn create_auth_services(
// Package service in Arc
let auth_application_service = Arc::new(auth_app_service);
// Account lockout service — in-memory brute-force protection
let login_lockout = Arc::new(
crate::infrastructure::services::login_lockout_service::LoginLockoutService::new(
config.auth.rate_limit.lockout_max_failures,
config.auth.rate_limit.lockout_duration_secs,
100_000, // Track up to 100k accounts concurrently
),
);
tracing::info!(
"Login lockout service initialized: max {} failures, {}s lockout",
config.auth.rate_limit.lockout_max_failures,
config.auth.rate_limit.lockout_duration_secs,
);
Ok(AuthServices {
token_service,
auth_application_service,
login_lockout,
})
}