Skip to content

webapi: Rate limit status endpoint. - #524

Merged
jholdstock merged 1 commit into
decred:masterfrom
jholdstock:statusrate
Aug 21, 2026
Merged

webapi: Rate limit status endpoint.#524
jholdstock merged 1 commit into
decred:masterfrom
jholdstock:statusrate

Conversation

@jholdstock

Copy link
Copy Markdown
Member

A rate limiter was already applied to the login webpage in order to prevent an attacker from brtue-forcing the admin password, however this defense was missing from the status endpoint which is protected by the same password.

A rate limiter was already applied to the login webpage in order to
prevent an attacker from brtue-forcing the admin password, however this
defense was missing from the status endpoint which is protected by the
same password.
@jholdstock
jholdstock merged commit 8c5ef8e into decred:master Aug 21, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants