security: add IP rate limiting + account lockout on auth endpoints
- Rate limit login (5/min), register (3/hr), refresh (10/min) per IP - Account lockout after 5 consecutive failed logins (15 min cooldown) - Fix stored XSS in admin panel (escapeHtml on all user-controlled data) - All limits configurable via OXICLOUD_RATE_LIMIT_* / OXICLOUD_LOCKOUT_* env vars - Zero new dependencies (uses existing moka crate for in-memory caches) - Includes unit tests for lockout service
This commit is contained in:
@@ -68,8 +68,23 @@ pub async fn create_auth_services(
|
||||
// Package service in Arc
|
||||
let auth_application_service = Arc::new(auth_app_service);
|
||||
|
||||
// Account lockout service — in-memory brute-force protection
|
||||
let login_lockout = Arc::new(
|
||||
crate::infrastructure::services::login_lockout_service::LoginLockoutService::new(
|
||||
config.auth.rate_limit.lockout_max_failures,
|
||||
config.auth.rate_limit.lockout_duration_secs,
|
||||
100_000, // Track up to 100k accounts concurrently
|
||||
),
|
||||
);
|
||||
tracing::info!(
|
||||
"Login lockout service initialized: max {} failures, {}s lockout",
|
||||
config.auth.rate_limit.lockout_max_failures,
|
||||
config.auth.rate_limit.lockout_duration_secs,
|
||||
);
|
||||
|
||||
Ok(AuthServices {
|
||||
token_service,
|
||||
auth_application_service,
|
||||
login_lockout,
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user