Skip to content

Throttle repeated failed Studio logins - #18

Merged
venkat1701 merged 2 commits into
mainfrom
fix/studio-login-throttle
Oct 4, 2026
Merged

venkat1701 merged 2 commits into
mainfrom
fix/studio-login-throttle

Conversation

@venkat1701

Copy link
Copy Markdown
Collaborator

Closes #4

POST /api/login accepted any number of attempts. It now tracks failures per client address: after 5 failures within 15 minutes the endpoint answers 429 with a short message saying when to try again, and a successful login clears the count. That matches the 5 attempt limit on the wire protocol.

The throttle lives in its own small class (LoginThrottle) with an injectable clock, so the window logic is tested without sleeping. The tracking map drops expired entries once it holds a few thousand addresses, so it can't grow without bound.

One thing to keep in mind: behind a reverse proxy every client shares the proxy's address. I didn't trust X-Forwarded-For here since anyone can send it.

Tests: LoginThrottleTest, plus repeatedFailedLoginsAreThrottled in StudioTest (the sixth attempt gets 429 even with the right password). Full ./mvnw install passes locally.

Five failed attempts from one address within 15 minutes now get a 429 until
the window ends, the same limit the wire protocol uses. Each attempt runs a
PBKDF2 hash, so unlimited retries were also an easy way to burn CPU.
@venkat1701
venkat1701 merged commit efaa85c into main Oct 4, 2026
@venkat1701
venkat1701 deleted the fix/studio-login-throttle branch October 4, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Studio login has no attempt limit

1 participant