aff270fa44a91b19ee7da7949dbf4023cb181d0e
/auth/login and /auth/refresh had no throttling, allowing unbounded password brute-force attempts. Add a process-local fixed-window limiter (10 requests/minute per client IP) in front of both. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Description
🎋Tanabata — web file manager with tags!
5.6 MiB
Languages
Go
49.6%
Svelte
39%
TypeScript
8.7%
PLpgSQL
1.4%
Dockerfile
0.5%
Other
0.8%