proudcity / wp-proudcity

The ProudCity WordPress platform
21 stars 9 forks source link

Brute force protection for Auth0 #2472

Open curtismchale opened 5 months ago

curtismchale commented 5 months ago

Source CM

We should lock an account if a password has been tried on it 5 times without success. I don't think we should put a time limit on it, or give any indication that they have a limited amount of tries. If there are 5 tries across a few weeks that don't work, we should still lock the account and the user can get in touch with us, or their site rep to get access to their account again.

I'd love to see a log action that we locked an account.

We may need to tweak the timeframe and number of attempts so that users aren't locked out too often.
