nickserv/security: password policy, auth throttle, unguessable codes
Three brute-force / weak-secret gaps closed: - REGISTER and SET PASSWORD now enforce a length range and reject a password equal to the nick (Anope's minpasslen/not-nick rules), with tests. - IDENTIFY is throttled per account: a few free tries then an exponential backoff that clears on success, so a password can't be ground down. SASL had a limiter; interactive login had none. - Emailed confirm/reset codes go from 6 digits to 8 base32 chars (~40 bits) and are burned after a few wrong guesses, closing a reset-code takeover window. Throttle and code state are node-local and in-memory (not in the event log).
This commit is contained in:
parent
75ba9b35b4
commit
f388e3d650
8 changed files with 189 additions and 19 deletions
|
|
@ -1411,7 +1411,7 @@ mod tests {
|
|||
e.handle(NetEvent::UserConnect { uid: "000AAAAAB".into(), nick: "newbie".into(), host: "h".into() });
|
||||
|
||||
// REGISTER with an email defers; complete it as the link layer would.
|
||||
let reg = e.handle(NetEvent::Privmsg { from: "000AAAAAB".into(), to: "42SAAAAAA".into(), text: "REGISTER pw newbie@example.org".into() });
|
||||
let reg = e.handle(NetEvent::Privmsg { from: "000AAAAAB".into(), to: "42SAAAAAA".into(), text: "REGISTER correcthorse newbie@example.org".into() });
|
||||
let (account, password, email, reply) = reg.iter().find_map(|a| match a {
|
||||
NetAction::DeferRegister { account, password, email, reply } => Some((account.clone(), password.clone(), email.clone(), reply.clone())),
|
||||
_ => None,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue