rnewson opened a new pull request, #5032:
URL: https://github.com/apache/couchdb/pull/5032

   ## Overview
   
   Enhance couchdb to efficiently reject requests for a given user if repeated 
requests have failed for authentication reasons, from the same IP address. This 
helps slow brute-force password attacks and is especially helpful if each 
authentication attempt is very expensive (pbkdf2 with a high iteration count, 
typically).
   
   ## Testing recommendations
   
   will be covered by automated tests
   
   ## Related Issues or Pull Requests
   
   
   ## Checklist
   
   - [x] Code is written and works correctly
   - [ ] Changes are covered by tests
   - [ ] Any new configurable parameters are documented in 
`rel/overlay/etc/default.ini`
   - [ ] Documentation changes were made in the `src/docs` folder
   - [ ] Documentation changes were backported (separated PR) to affected 
branches
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to