Closed rr8733380 closed 1 year ago
Users don't affect each other if they are real users.
But it's not like that. They try to log in, but they can't because they don't get the code. I try to log in from my number myself, but the code still doesn't come. Could it be because these are users from Russia and they use Russian numbers?
It shouldn't be the case.
I noticed a problem with authorization.
Let's say I have 50 users.
25 users entered their phone number and received a confirmation code. They have successfully logged in. Then the twenty-sixth user comes and enters his phone numbers many times. As a result, he gets an error - Too many requests: retry after 59964. He can't get in.
Then the other 24 users come in, enter their phone number and they don't get the code. Moreover, they do not display an error of the type - "Too many requests". They downloaded my app for the first time and entered their phone number for the first time.
It turns out that users cannot log into my application. One person can break the operation of an entire application.
Can you fix it? It's impossible to work like this.