Auth: Add setting to disable username based brute force login protection (#109152)
* Add setting to disable username based brute force login protection * Use new DisableUsernameLoginProtection setting in tests where appropriate * Update documentation for other brute force directives * Avoid unecessary database calls * Add test cases for username and IP protection settings
This commit is contained in:
@@ -371,6 +371,9 @@
|
||||
# max number of failed login attempts before user gets locked
|
||||
;brute_force_login_protection_max_attempts = 5
|
||||
|
||||
# disable protection against brute force login attempts by username
|
||||
;disable_username_login_protection = false
|
||||
|
||||
# disable protection against brute force login attempts by IP address
|
||||
; disable_ip_address_login_protection = true
|
||||
|
||||
|
||||
Reference in New Issue
Block a user