Ratelimit password reset by email instead of IP.
Also changed `password_reset` endpoint rate limit configuration to 1/minute from 30/5 minutes. PROD-1427
Showing
- common/djangoapps/util/request_rate_limiter.py 10 additions, 1 deletioncommon/djangoapps/util/request_rate_limiter.py
- openedx/core/djangoapps/user_authn/views/password_reset.py 11 additions, 7 deletionsopenedx/core/djangoapps/user_authn/views/password_reset.py
- openedx/core/djangoapps/user_authn/views/tests/test_reset_password.py 8 additions, 9 deletions.../djangoapps/user_authn/views/tests/test_reset_password.py
Please register or sign in to comment