Skip to content

BA-020 — Add login and refresh rate limiting #588

Description

@MaryammAli
  • Type: Security
  • Affected area: auth controllers, throttling configuration
  • BackendAcademy
  • Summary: Session endpoints are high-value abuse targets and need separate limits from ordinary API traffic.
  • Acceptance criteria: Limits are applied per IP and account identifier; responses include retry metadata; limits are configurable and observable.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave program

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions