arcus.webapi
arcus.webapi copied to clipboard
Provide 'too many failed authentication attempts' security alert
Is your feature request related to a problem? Please describe. We already write a security event upon successful van failed authentication, but we do nothing we possible malicious activity that could be detected with too many failed authentication attempts.
Describe the solution you'd like We should consider adding a configurable threshold that will track a security alert when too many failed authentications are being monitored.
Describe alternatives you've considered This could also reflect in the HTTP response, but maybe in a later phase.
Would it be possible to disable this as well ?
Would it be possible to disable this as well ?
Yes, of course, will like the general security events probably an opt-in feature.
Prioritizing .NET 8 support, moving to v2.1.