Skip to content
This repository has been archived by the owner on May 15, 2020. It is now read-only.

MFA: SMS code rate limiting (no more than 10 codes per person, per minute) #49

Open
kevinmichaelchen opened this issue Feb 19, 2018 · 0 comments

Comments

@kevinmichaelchen
Copy link
Member

Don't transmit more than N SMS messages to personId within the last M minutes.

The table needs to maintain a transmittedAt timestamp.

N and M should be configurable via env vars, with sane defaults.

10 codes in the last 5 minutes is too much.

@kevinmichaelchen kevinmichaelchen changed the title MFA: Rate limiting MFA: SMS code rate limiting (no more than 10 codes per person, per minute) Feb 27, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant