piccolo_admin icon indicating copy to clipboard operation
piccolo_admin copied to clipboard

Ratelimits to prevent mass nukes

Open cheesycod opened this issue 4 years ago • 2 comments

It would be nice if piccolo admin allowed ratelimiting non super users to protect against account compromises.

cheesycod avatar Jun 02 '21 14:06 cheesycod

There's currently an option in create_admin, which is rate_limit_provider. This is just applied to the login endpoint. It's not documented very well at the moment.

Were you thinking of just protecting the login endpoint, or all endpoints?

dantownsend avatar Jun 03 '21 19:06 dantownsend

All endpoints

cheesycod avatar Jun 04 '21 04:06 cheesycod