Page MenuHomePhabricator

Add a rate limit to generating new account recovery links for a given account
ClosedPublic

Authored by epriestley on Jul 19 2019, 4:42 PM.
Tags
None
Referenced Files
F15462470: D20666.diff
Tue, Apr 1, 3:16 PM
F15461242: D20666.id49293.diff
Tue, Apr 1, 6:34 AM
F15459968: D20666.id49306.diff
Mon, Mar 31, 6:42 PM
F15455282: D20666.id49293.diff
Sat, Mar 29, 11:17 PM
F15451714: D20666.id.diff
Fri, Mar 28, 11:29 PM
F15446230: D20666.diff
Thu, Mar 27, 5:52 PM
F15445294: D20666.diff
Thu, Mar 27, 1:19 PM
F15439410: D20666.id49293.diff
Wed, Mar 26, 7:24 AM
Subscribers
None

Details

Summary

Depends on D20665. Ref T13343. We support CAPTCHAs on the "Forgot password?" flow, but not everyone configures them (or necessarily should, since ReCAPTCHA is a huge external dependency run by Google that requires you allow Google to execute JS on your domain) and the rate at which any reasonable user needs to take this action is very low.

Put a limit on the rate at which account recovery links may be generated for a particular account, so the worst case is a trickle of annoyance rather than a flood of nonsense.

Test Plan

Screen Shot 2019-07-19 at 9.39.15 AM.png (729×1 px, 139 KB)

Diff Detail

Repository
rP Phabricator
Branch
elogin5
Lint
Lint Passed
Unit
Tests Passed
Build Status
Buildable 23160
Build 31809: Run Core Tests
Build 31808: arc lint + arc unit