Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

【安全】密码试错次数超过设置,自动锁定账户对admin无效 #810

Closed
pagezz-canway opened this issue Nov 21, 2022 · 4 comments
Assignees
Milestone

Comments

@pagezz-canway
Copy link

用文字描述你遇到的问题

密码试错次数超过设置,自动锁定账户对admin无效

重现方法

1.对默认目录设置密码试错次为3
image

2.登录时使用admin,故意输错密码超过3次,发现一直可以重试,账户未锁定
image

预期行为

输错密码超过3次,提示密码被锁定,需要X秒后重试

版本

  • 提供用户管理的具体版本号
    2.5.1
  • 是否是企业版问题?

如果是 SaaS 页面问题,请提供使用的操作系统和浏览器信息

  • OS: [e.g. iOS]
  • Browser [e.g. chrome, safari]
  • Version [e.g. 22]

额外信息

任何你觉得有助于问题解决的内容

@wklken
Copy link
Collaborator

wklken commented Nov 21, 2022

@wklken
Copy link
Collaborator

wklken commented Nov 22, 2022

难易度: 简单
工作量: s

确认原来为啥不检查, 没问题后变更判断条件, 自测, 推 PR 过来
注意需要确认下单测会不会挂, 单测如果原先有登录检查的, 需要补充admin用户作为用户数据, 跑单测

@Canway-shiisa Canway-shiisa self-assigned this Nov 28, 2022
@Xmandon Xmandon added this to the Y2022M48 milestone Nov 28, 2022
@Canway-shiisa
Copy link
Contributor

追溯不到当时具体的原因,跟blues沟通后判断应该是当时特意留的一个口子,@Xmandon 看下是否清楚

@wklken
Copy link
Collaborator

wklken commented Dec 2, 2022

可以去掉条件判断后测试一下, 相当于admin登录当成普通用户处理 => 没问题的话推个 PR

记得加一行注释说明原来有这么一个条件现在因为什么原因去掉了

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants