services: throttle emailed codes to stop RESEND/RESETPASS email-bombing
All checks were successful
CI / check (push) Successful in 3m46s

REGISTER was rate-limited but RESEND and RESETPASS weren't — anyone could
repeatedly request confirmation/reset codes for any account with an address
on file, flooding the victim's inbox and burning the service's sender
reputation. A per-account 60s cooldown (code_issue_wait, mirroring the vhost
request throttle) now gates both paths; guessing was already infeasible
(2^40 code + 5-try limit), so this closes the abuse, not an auth hole.
This commit is contained in:
Jean Chevronnet 2026-07-16 10:41:52 +00:00
parent 320a591ae3
commit 61005f52f5
No known key found for this signature in database
7 changed files with 44 additions and 1 deletions

View file

@ -953,6 +953,8 @@ pub trait Store {
fn vhost_owner(&self, host: &str) -> Option<String>;
fn request_vhost(&mut self, account: &str, host: &str) -> Result<(), RegError>;
fn vhost_request_wait(&self, account: &str) -> u64;
// Seconds before another emailed code may be issued for this account (0 = now).
fn code_issue_wait(&self, account: &str) -> u64;
fn take_vhost_request(&mut self, account: &str) -> Result<Option<String>, RegError>;
fn vhost_requests(&self) -> Vec<(String, String)>;
fn vhost_offer_add(&mut self, host: &str) -> Result<bool, RegError>;