0
Fork 0
mirror of https://github.com/TryGhost/Ghost.git synced 2025-02-24 23:48:13 -05:00
ghost/core/server
Fabien 'egg' O'Carroll 1af2b50dcf
Added userAuth brute middleware to members auth endpoint (#13152)
refs https://github.com/TryGhost/Team/issues/696

The userAuth spam prevention logic is reused, but a new piece of
middleware has to be created so that we can use a custom lookup key to
conatin the member email.

We must also add json parsing middleware to the route so that the brute
middleware can read the email.

The express body-parser middleware handles multiple instances on the
same route, so this doesn't cause problems upstream.

https://github.com/expressjs/body-parser/blob/1.19.0/lib/types/json.js#L99-L103
2021-07-19 09:40:38 +01:00
..
adapters Fixed slow-running scheduling default test 2021-07-15 13:50:59 +04:00
api Moved labs utlity to shared 2021-07-08 09:05:41 +01:00
data Removed use of deprecated new Error() syntax 2021-07-14 12:16:44 +04:00
lib Moved settings/cache to shared/settings-cache 2021-06-30 15:49:10 +01:00
models 🐛 Fixed error on saving member with existing label 2021-07-16 14:01:47 +05:30
public
services 🐛 Fixed alt="null" for feature image in emails 2021-07-15 09:44:34 +01:00
views
web Added userAuth brute middleware to members auth endpoint (#13152) 2021-07-19 09:40:38 +01:00
analytics-events.js Added comments to all usages of lib/common/events 2021-07-07 16:02:44 +01:00
ghost-server.js Switch to @tryghost/debug, remove ghost-ignition 2021-06-15 17:24:22 +01:00
notify.js Change to use @tryghost/logging 2021-06-15 15:59:11 +01:00
overrides.js
run-update-check.js Added protective code to update-check job 2021-06-29 14:02:16 +04:00
update-check.js Fixed critical alerts sending to admin users 2021-07-07 11:29:18 +04:00