fix: resolve auth security issues - 2FA require TOTP on disable, rate limiting, timing-safe login, token expiry check

This commit is contained in:
remco committed 2026-07-02 14:54:25 +02:00
1 parent 4a06b30263
commit 64f50b2dde
6 files changed
+63 -9

No files matched your search

+7 -1
View File
@@ -73,6 +73,11 @@ export default async function TwoFactorPage({
{t("badCode")}
</p>
) : null}
{sp.error === "ratelimit" ? (
<p style={{ color: "var(--color-danger)", marginTop: 0 }}>
{t("rateLimit")}
</p>
) : null}
{!hasAppKey ? (
<p style={{ margin: 0 }}>
@@ -84,7 +89,8 @@ export default async function TwoFactorPage({
<p style={{ marginTop: 0 }}>
<strong>{t("isEnabled")}</strong> {t("onYourAccount")}
</p>
<form action={disableTwoFactor}>
<form action={disableTwoFactor} style={{ display: "flex", gap: "0.5rem" }}>
<input name="code" placeholder={t("codePlaceholder")} inputMode="numeric" required />
<button type="submit" className="btn btn-danger">
{t("disable")}
</button>