shoc-backend/SeaHaven.DataServices
Alexandre Brandizzi 77a10e38ca fix(auth): cap reset abuse per account, key code hashes, send reset email off the request path
- Forgot Password is limited to 3 codes an hour and 10 a day per email, and
  an account gets 10 failed code checks a day across every code it is sent,
  so new client addresses and new codes no longer buy more guesses. Refused
  requests answer exactly like accepted ones.
- The reset email is queued to a background sender, and unregistered
  addresses store a row no code can match, so both paths do the same work
  and return without waiting on the mail provider. Each request also clears
  expired codes.
- Code hashes are HMAC-SHA256 under a key derived with HKDF from the JWT
  signing secret; rows in the previous unkeyed format stop matching.
- Email and code are read only from the JSON body.
2026-09-25 13:00:03 -03:00
..
DependencyInjection backend changes 2026-05-14 11:00:12 -05:00
Dto feat(team-members): support pending member creation (SH-325) 2026-09-16 21:41:55 -03:00
Exceptions fix: map concurrent uplift inserts to conflict 2026-09-23 01:26:15 -03:00
Helpers Sites API: site code uniqueness, soft delete with role check, open work orders, site notes 2026-09-25 11:19:29 -03:00
Implementation fix(auth): cap reset abuse per account, key code hashes, send reset email off the request path 2026-09-25 13:00:03 -03:00
Interfaces fix(auth): cap reset abuse per account, key code hashes, send reset email off the request path 2026-09-25 13:00:03 -03:00
Models feat(notifications): SEV response-window alerts and breach acknowledgement 2026-09-25 11:16:21 -03:00
Properties fix: distinguish uplift request key conflicts 2026-09-23 01:39:16 -03:00
SeaHaven.DataServices.csproj refactor 2026-04-28 18:55:14 -05:00