gcdevops / HRWhiteListing

MIT License
2 stars 0 forks source link

Limit login attempts #163

Closed jaysonmc closed 4 years ago

jaysonmc commented 4 years ago

Security Controls - AC-7

Application should limit log in attempts to 3 invalid login attempts over a period of 15 minutes. When limit reached, lock for 30 minutes


https://github.com/odoo/odoo/blob/13.0/odoo/addons/base/models/ir_config_parameter.py

_default_parameters = { "database.secret": lambda: str(uuid.uuid4()), "database.uuid": lambda: str(uuid.uuid1()), "database.create_date": fields.Datetime.now, "web.base.url": lambda: "http://localhost:%s" % config.get('http_port'), "base.login_cooldown_after": lambda: 10, "base.login_cooldown_duration": lambda: 60, }