Description
Problem
Public password, passkey, and signup routes are mounted without throttling in internal/server/server.go:84-89 and internal/server/ui_routes.go:9-16. Only the authenticated API group receives the 15-second middleware timeout (internal/server/server.go:97-100), while the HTTP server sets only ReadHeaderTimeout (cmd/trackd/main.go:101-105).
A valid-username password attempt reaches bcrypt on every request (internal/store/accounts.go:110-153). There is no application rate limiter or documented upstream WAF/rate-limit requirement.
Impact
- Online password guessing is unbounded.
- Requests for known usernames can consume bcrypt CPU and degrade availability.
- Slow request bodies on public/UI routes can hold connections and goroutines after headers complete.
Acceptance criteria
- Apply bounded per-IP and per-account/identifier limits to password and passkey login/reauth/options endpoints; return 429 with
Retry-After. - Add request/body deadlines appropriate for normal form, JSON, multipart, and WebAuthn ceremonies without timing out WebSockets.
- Document any required trusted-proxy/IP handling.
- Add tests for limit exhaustion, recovery, and slow-request cancellation.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.