Enable Devise :lockable — brute-force protection on /users/sign_in

User model already includes :lockable (DB columns are migrated) but the
config block in `devise.rb` was entirely commented out, so the strategy
defaulted to :none — no lockout, no rate limit, nothing standing between
the internet and Devise's bcrypt loop.

Self-hosted deployments expose docuseal.<apex>/users/sign_in publicly
(the embedded builder requires an admin session). Lock the account on
10 failed attempts, recover via email OR 1-hour wait.
pull/697/head
Vadym Shaveiko 3 months ago
parent e59c8b421e
commit b66ccdc206

@ -218,27 +218,17 @@ Devise.setup do |config|
# config.timeout_in = 30.minutes # config.timeout_in = 30.minutes
# ==> Configuration for :lockable # ==> Configuration for :lockable
# Defines which strategy will be used to lock an account. # The User model declares `:lockable` so the columns exist; without the
# :failed_attempts = Locks an account after a number of failed attempts to sign in. # config below the strategy is :none → no brute-force protection on
# :none = No lock strategy. You should handle locking by yourself. # /users/sign_in. Self-hosted DocuSeal exposes that endpoint publicly
# config.lock_strategy = :failed_attempts # at docuseal.<apex>, so lock the account on 10 wrong attempts and
# require an unlock email OR 1h wait to recover.
# Defines which key will be used when locking and unlocking an account config.lock_strategy = :failed_attempts
# config.unlock_keys = [:email] config.unlock_keys = [:email]
config.unlock_strategy = :both
# Defines which strategy will be used to unlock an account. config.maximum_attempts = 10
# :email = Sends an unlock link to the user email config.unlock_in = 1.hour
# :time = Re-enables login after a certain amount of time (see :unlock_in below) config.last_attempt_warning = true
# :both = Enables both strategies
# :none = No unlock strategy. You should handle unlocking by yourself.
# config.unlock_strategy = :both
# Number of authentication tries before locking an account if lock_strategy
# is failed attempts.
# config.maximum_attempts = 20
# Time interval to unlock the account if :time is enabled as unlock_strategy.
# config.unlock_in = 1.hour
# Warn on the last attempt before the account is locked. # Warn on the last attempt before the account is locked.
# config.last_attempt_warning = true # config.last_attempt_warning = true

Loading…
Cancel
Save