shoc-backend/SeaHaven.Services/Interfaces/IPasswordResetThrottle.cs
Alexandre Brandizzi 77a10e38ca fix(auth): cap reset abuse per account, key code hashes, send reset email off the request path
- Forgot Password is limited to 3 codes an hour and 10 a day per email, and
  an account gets 10 failed code checks a day across every code it is sent,
  so new client addresses and new codes no longer buy more guesses. Refused
  requests answer exactly like accepted ones.
- The reset email is queued to a background sender, and unregistered
  addresses store a row no code can match, so both paths do the same work
  and return without waiting on the mail provider. Each request also clears
  expired codes.
- Code hashes are HMAC-SHA256 under a key derived with HKDF from the JWT
  signing secret; rows in the previous unkeyed format stop matching.
- Email and code are read only from the JSON body.
2026-09-25 13:00:03 -03:00

24 lines
939 B
C#

namespace SeaHaven.Services.Interfaces
{
/// <summary>
/// Per-account limits on the anonymous password reset flow, keyed on the
/// normalized email so they hold however many client addresses an attacker uses.
/// </summary>
public interface IPasswordResetThrottle
{
/// <summary>
/// Counts a code request for the email and returns true while it is within the
/// hourly and daily limits. A refused request is not counted.
/// </summary>
bool TryAcceptCodeRequest(string email);
/// <summary>
/// Reserves one failed check for the email before a code is compared. Returns
/// false once the account has used its failed checks for the window.
/// </summary>
bool TryReserveCheck(string email);
/// <summary>Gives back the reservation of a check whose code matched.</summary>
void ReleaseCheck(string email);
}
}