fix: resolve auth security issues - 2FA require TOTP on disable, rate limiting, timing-safe login, token expiry check
This commit is contained in:
1 parent
4a06b30263
commit
64f50b2dde
6 files changed
+63
-9
No files matched your search
@@ -73,6 +73,11 @@ export default async function TwoFactorPage({
|
||||
{t("badCode")}
|
||||
</p>
|
||||
) : null}
|
||||
{sp.error === "ratelimit" ? (
|
||||
<p style={{ color: "var(--color-danger)", marginTop: 0 }}>
|
||||
{t("rateLimit")}
|
||||
</p>
|
||||
) : null}
|
||||
|
||||
{!hasAppKey ? (
|
||||
<p style={{ margin: 0 }}>
|
||||
@@ -84,7 +89,8 @@ export default async function TwoFactorPage({
|
||||
<p style={{ marginTop: 0 }}>
|
||||
<strong>{t("isEnabled")}</strong> {t("onYourAccount")}
|
||||
</p>
|
||||
<form action={disableTwoFactor}>
|
||||
<form action={disableTwoFactor} style={{ display: "flex", gap: "0.5rem" }}>
|
||||
<input name="code" placeholder={t("codePlaceholder")} inputMode="numeric" required />
|
||||
<button type="submit" className="btn btn-danger">
|
||||
{t("disable")}
|
||||
</button>
|
||||
|
||||
Reference in new issue
Block a user