filesender / governance

Governance and policies for the FileSender software development
0 stars 0 forks source link

MoU14 m2 complete: Address test for missing rate limiting on email functionality ( 5.1.2 ) #27

Closed monkeyiq closed 1 year ago

monkeyiq commented 2 years ago

This was resolved with https://github.com/filesender/filesender/pull/1260

The milestone text:

A security audit found that FileSender was missing rate limiting functionality for email as listing in section 5.1.2 of that report. The following actions Download file, Create guest voucher, Start guest upload, Request transfer logs, Send reminder to specific recipient.

meijer commented 1 year ago

Recommended to board to accept

meijer commented 1 year ago

Board accepted. Nils reports that it might be the case that ratelimit entries don't get cleaned, can you please have a glance at that?