How can I limit login attempts in Spring Security?

后端 未结 7 1454
清酒与你
清酒与你 2020-12-08 08:11

Is there some configuration or available module in Spring Security to limit login attempts (ideally, I\'d like to have an increasing wait time between subsequent failed atte

7条回答
  •  醉酒成梦
    2020-12-08 08:24

    Implement an AuthenticationFailureHandler that updates a count/time in the DB. I wouldn't count on using the session because the attacker is not going to be sending cookies anyway.

提交回复
热议问题