Skip to content

BA-020 — Add login and refresh rate limiting #588

Description

@MaryammAli
  • Type: Security
  • Affected area: auth controllers, throttling configuration
  • BackendAcademy
  • Summary: Session endpoints are high-value abuse targets and need separate limits from ordinary API traffic.
  • Acceptance criteria: Limits are applied per IP and account identifier; responses include retry metadata; limits are configurable and observable.

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave program

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions