mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 03:43:11 +00:00
- Forgot Password is limited to 3 codes an hour and 10 a day per email, and an account gets 10 failed code checks a day across every code it is sent, so new client addresses and new codes no longer buy more guesses. Refused requests answer exactly like accepted ones. - The reset email is queued to a background sender, and unregistered addresses store a row no code can match, so both paths do the same work and return without waiting on the mail provider. Each request also clears expired codes. - Code hashes are HMAC-SHA256 under a key derived with HKDF from the JWT signing secret; rows in the previous unkeyed format stop matching. - Email and code are read only from the JSON body.
24 lines
939 B
C#
24 lines
939 B
C#
namespace SeaHaven.Services.Interfaces
|
|
{
|
|
/// <summary>
|
|
/// Per-account limits on the anonymous password reset flow, keyed on the
|
|
/// normalized email so they hold however many client addresses an attacker uses.
|
|
/// </summary>
|
|
public interface IPasswordResetThrottle
|
|
{
|
|
/// <summary>
|
|
/// Counts a code request for the email and returns true while it is within the
|
|
/// hourly and daily limits. A refused request is not counted.
|
|
/// </summary>
|
|
bool TryAcceptCodeRequest(string email);
|
|
|
|
/// <summary>
|
|
/// Reserves one failed check for the email before a code is compared. Returns
|
|
/// false once the account has used its failed checks for the window.
|
|
/// </summary>
|
|
bool TryReserveCheck(string email);
|
|
|
|
/// <summary>Gives back the reservation of a check whose code matched.</summary>
|
|
void ReleaseCheck(string email);
|
|
}
|
|
}
|