In addition, something I've discovered, you should store failed login attempts for invalid usernames as well. If you only ever lockout failed attempts on valid usernames, then you are revealing which usernames are valid which is a no-no.
-
Notifications
You must be signed in to change notification settings - Fork 0
thevinitgupta/lynkit-backend
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
REST API server for URL Shortner Application - Lynkit
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published