namespace SeaHaven.Services.Interfaces { /// /// Per-account limits on the anonymous password reset flow, keyed on the /// normalized email so they hold however many client addresses an attacker uses. /// public interface IPasswordResetThrottle { /// /// Counts a code request for the email and returns true while it is within the /// hourly and daily limits. A refused request is not counted. /// bool TryAcceptCodeRequest(string email); /// Gives back an accepted code request whose email could not be queued. void ReleaseCodeRequest(string email); /// /// Reserves one failed check for the email before a code is compared. Returns /// false once the account has used its failed checks for the window. /// bool TryReserveCheck(string email); /// /// Gives back a reservation that did not become a failed guess: the code matched, /// or there was no live code to compare it with. /// void ReleaseCheck(string email); } }