trackslash
TRACK-1 P1

Rate-limit and deadline public authentication endpoints

0
All issues

Description

Problem

Public password, passkey, and signup routes are mounted without throttling in internal/server/server.go:84-89 and internal/server/ui_routes.go:9-16. Only the authenticated API group receives the 15-second middleware timeout (internal/server/server.go:97-100), while the HTTP server sets only ReadHeaderTimeout (cmd/trackd/main.go:101-105).

A valid-username password attempt reaches bcrypt on every request (internal/store/accounts.go:110-153). There is no application rate limiter or documented upstream WAF/rate-limit requirement.

Impact

  • Online password guessing is unbounded.
  • Requests for known usernames can consume bcrypt CPU and degrade availability.
  • Slow request bodies on public/UI routes can hold connections and goroutines after headers complete.

Acceptance criteria

  • Apply bounded per-IP and per-account/identifier limits to password and passkey login/reauth/options endpoints; return 429 with Retry-After.
  • Add request/body deadlines appropriate for normal form, JSON, multipart, and WebAuthn ceremonies without timing out WebSockets.
  • Document any required trusted-proxy/IP handling.
  • Add tests for limit exhaustion, recovery, and slow-request cancellation.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.