Rate limit account authentication attempts

This commit is contained in:
Hamza Ayed
2026-10-03 00:59:47 +03:00
parent f745bed0f7
commit 5430d4ac4b
6 changed files with 165 additions and 4 deletions
+14
View File
@@ -185,6 +185,20 @@ class AuthenticationTests(unittest.TestCase):
)
self.assertEqual(duplicate.status_code, 409, duplicate.text)
def test_login_failures_are_rate_limited_and_expire(self) -> None:
email = f"{uuid4().hex}@example.test"
client_host = f"rate-limit-test-{uuid4().hex}"
now = 1_800_000_000
for _ in range(auth.LOGIN_FAILURE_LIMIT):
auth.record_login_failure(email, client_host, now=now)
self.assertEqual(auth.login_retry_after(email, client_host, now=now), 900)
self.assertEqual(
auth.login_retry_after(email, client_host, now=now + auth.LOGIN_WINDOW_SECONDS),
0,
)
auth.clear_login_failures(email, client_host)
def test_local_bootstrap_is_restricted_to_loopback_clients(self) -> None:
remote = self.client.post("/v1/auth/local-session", json={})
self.assertEqual(remote.status_code, 403, remote.text)