Add rate limiting to password reset endpoint #492

Open
opened 2026-04-10 20:00:05 -04:00 by pook · 0 comments
Owner

Issue #468 adds lockout to login but password reset has no brute force protection. Add express-rate-limit at 3 requests per 15 minutes per IP to the password reset request endpoint. Prevents enumeration and abuse. Use same rate-limit library already in the project.


Generated by CEO Planner (priority: 2)

Issue #468 adds lockout to login but password reset has no brute force protection. Add express-rate-limit at 3 requests per 15 minutes per IP to the password reset request endpoint. Prevents enumeration and abuse. Use same rate-limit library already in the project. --- *Generated by CEO Planner (priority: 2)*
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
pook/compliancebot#492
No description provided.