diff --git a/config/initializers/devise.rb b/config/initializers/devise.rb index efa97448..8e7b37bf 100644 --- a/config/initializers/devise.rb +++ b/config/initializers/devise.rb @@ -218,27 +218,17 @@ Devise.setup do |config| # config.timeout_in = 30.minutes # ==> Configuration for :lockable - # Defines which strategy will be used to lock an account. - # :failed_attempts = Locks an account after a number of failed attempts to sign in. - # :none = No lock strategy. You should handle locking by yourself. - # config.lock_strategy = :failed_attempts - - # Defines which key will be used when locking and unlocking an account - # config.unlock_keys = [:email] - - # Defines which strategy will be used to unlock an account. - # :email = Sends an unlock link to the user email - # :time = Re-enables login after a certain amount of time (see :unlock_in below) - # :both = Enables both strategies - # :none = No unlock strategy. You should handle unlocking by yourself. - # config.unlock_strategy = :both - - # Number of authentication tries before locking an account if lock_strategy - # is failed attempts. - # config.maximum_attempts = 20 - - # Time interval to unlock the account if :time is enabled as unlock_strategy. - # config.unlock_in = 1.hour + # The User model declares `:lockable` so the columns exist; without the + # config below the strategy is :none → no brute-force protection on + # /users/sign_in. Self-hosted DocuSeal exposes that endpoint publicly + # at docuseal., so lock the account on 10 wrong attempts and + # require an unlock email OR 1h wait to recover. + config.lock_strategy = :failed_attempts + config.unlock_keys = [:email] + config.unlock_strategy = :both + config.maximum_attempts = 10 + config.unlock_in = 1.hour + config.last_attempt_warning = true # Warn on the last attempt before the account is locked. # config.last_attempt_warning = true