FerryDocs
ArchitectureSecurity model

The limit on failed sign-ins

After 10 failed sign-ins in 5 minutes, the server refuses each sign-in for a short time.

Edit on GitHub
Another personwrong passwordAdministratorServer10 failures

A person tries wrong passwords. The server counts each failure.

1 / 4

The limit makes it slow to guess the password. It applies to sign-ins and to attempts to create the account.

RuleValue
Failures before the refusal10 in 5 minutes
Answer during the refusal429 too_many_attempts
End of the refusalWhen the oldest failure is 5 minutes old

The limit is not per IP address

The server has one counter for all callers. A person who can reach the API can thus delay the sign-in of the administrator. This is one more reason to keep the API on localhost or behind HTTPS.

What to do

Keep the API away from the internet. See What listens where and Reach the API through SSH.

On this page