Skip to content

#615 Add per-email rate limiting to forgotPassword #318

@vic-Gray

Description

@vic-Gray

Area: security · Effort: S\n\nWhat: Add rate limiting so the same email address cannot trigger repeated password reset emails.\n\nWhy: Without this, the endpoint can be abused to spam users.\n\nHints:\n- backend/src/auth/auth.service.ts\n- Store a cooldown key in Redis keyed by email

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions