nickserv/security: password policy, auth throttle, unguessable codes
Three brute-force / weak-secret gaps closed: - REGISTER and SET PASSWORD now enforce a length range and reject a password equal to the nick (Anope's minpasslen/not-nick rules), with tests. - IDENTIFY is throttled per account: a few free tries then an exponential backoff that clears on success, so a password can't be ground down. SASL had a limiter; interactive login had none. - Emailed confirm/reset codes go from 6 digits to 8 base32 chars (~40 bits) and are burned after a few wrong guesses, closing a reset-code takeover window. Throttle and code state are node-local and in-memory (not in the event log).
This commit is contained in:
parent
75ba9b35b4
commit
f388e3d650
8 changed files with 189 additions and 19 deletions
|
|
@ -8,6 +8,10 @@ pub fn handle(me: &str, from: &Sender, args: &[&str], ctx: &mut ServiceCtx) {
|
|||
ctx.notice(me, from.uid, "Syntax: REGISTER <password> [email]");
|
||||
return;
|
||||
};
|
||||
if let Err(reason) = crate::password::validate_password(password, from.nick) {
|
||||
ctx.notice(me, from.uid, reason);
|
||||
return;
|
||||
}
|
||||
let email = args.get(2).map(|s| s.to_string());
|
||||
ctx.defer_register(from.nick, *password, email, RegReply::NickServ {
|
||||
agent: me.to_string(),
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue