Add account lockout after 10 consecutive failed login attempts #974

Open
opened 2026-04-12 06:33:31 -04:00 by pook · 0 comments
Owner

Implement account lockout mechanism: after 10 consecutive failed login attempts on an account, lock the account for 30 minutes. Store failed attempt count and lockout timestamp. Return 403 with appropriate message when locked. Reset counter on successful login. Add integration test verifying lockout triggers at 10 failures and unlocks after timeout. This parallels contractpilot's #886 for consistency across products.


Generated by CEO Planner (priority: 2)

Implement account lockout mechanism: after 10 consecutive failed login attempts on an account, lock the account for 30 minutes. Store failed attempt count and lockout timestamp. Return 403 with appropriate message when locked. Reset counter on successful login. Add integration test verifying lockout triggers at 10 failures and unlocks after timeout. This parallels contractpilot's #886 for consistency across products. --- *Generated by CEO Planner (priority: 2)*
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
pook/compliancebot#974
No description provided.