Software /
code /
prosody-modules
File
mod_limit_auth/README.markdown @ 5406:b86d80e21c60
mod_http_oauth2: Validate consistency of response and grant types
Ensure that these correlated fields make sense per RFC 7591 § 2.1, even
though we currently only check the response type during authorization.
This could probably all be deleted if (when!) we remove the implicit
grant, since then these things don't make any sense anymore.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Tue, 02 May 2023 16:34:31 +0200 |
parent | 2121:4916c1b6517f |
line wrap: on
line source
--- summary: Throttle authentication attempts with optional tarpit ... Introduction ============ This module lets you put a per-IP limit on the number of failed authentication attempts. It features an optioanal [tarpit](https://en.wikipedia.org/wiki/Tarpit_%28networking%29), i.e. waiting some time before returning an "authentication failed" response. Configuration ============= ``` {.lua} modules_enabled = { -- your other modules "limit_auth"; } limit_auth_period = 30 -- over 30 seconds limit_auth_max = 5 -- tolerate no more than 5 failed attempts -- Will only work with Prosody trunk: limit_auth_tarpit_delay = 10 -- delay answer this long ``` Compatibility ============= Requires 0.9 or later. The tarpit feature requires Prosody trunk.