Security: Add rate limiting to auth endpoints #13
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
The login and register endpoints don't have rate limiting, making them vulnerable to brute force attacks.
Location
backend/app/Http/Controllers/Api/V1/AuthController.php:13backend/app/Http/Controllers/Api/V1/AuthController.php:35Acceptance Criteria
Related