View Issue Details

IDProjectCategoryView StatusLast Update
0009271Talerlibeufin-bankpublic2024-11-21 00:00
ReporterAntoine A Assigned ToAntoine A  
PriorityurgentSeverityfeatureReproducibilityN/A
Status resolvedResolutionfixed 
Target Version0.14Fixed in Version0.14 
Summary0009271: Lockout policy
DescriptionEvery bank account should have a password authentication attempt counter that blocks the account after N failed attempts.
When an account is blocked, existing tokens still work, but password authentication no longer does.
It's also important not to perform password hashing when an account is blocked, as we also want to become more DOS-resistant.
TagsNo tags attached.

Relationships

related to 0009272 resolvedAntoine A Password recovery and account unlocking 
child of 0009269 resolvedAntoine A Password and lockout policy 

Activities

Antoine A

2024-11-18 18:12

developer   ~0023732

Fixed in 5f53f42899821e4fb7e353ae5ec6b76981ee5dd9

Issue History

Date Modified Username Field Change
2024-10-15 17:51 Antoine A New Issue
2024-10-15 17:51 Antoine A Status new => assigned
2024-10-15 17:51 Antoine A Assigned To => Antoine A
2024-10-15 17:51 Antoine A Relationship added child of 0009269
2024-10-15 18:29 Antoine A Relationship added related to 0009272
2024-11-18 18:12 Antoine A Status assigned => resolved
2024-11-18 18:12 Antoine A Resolution open => fixed
2024-11-18 18:12 Antoine A Note Added: 0023732
2024-11-21 00:00 Christian Grothoff Fixed in Version => 0.14
2024-11-21 00:00 Christian Grothoff Target Version 1.0 => 0.14