mediawiki: try disabling loginattemptthrottle entirely
Sometimes folks are unable to login to the wiki because there have been too many login attempts from the proxy they happen to be hitting the wiki from. Lets just disable this throttle entirely, as brute force won't work ever anyhow. Signed-off-by: Kevin Fenzi <kevin@scrye.com>
This commit is contained in:
parent
7763c3c6c3
commit
bd7e118855
1 changed files with 3 additions and 12 deletions
|
@ -648,18 +648,9 @@ $_SERVER['HTTP_HOST'] = 'fedoraproject.org';
|
|||
$_SERVER['REQUEST_SCHEME'] = 'https';
|
||||
$_SERVER['SERVER_PORT'] = 443;
|
||||
|
||||
#
|
||||
# increase password/login attempts because we use memcached and someone could
|
||||
# lock a proxy out by simply trying to login from that ip a bunch of times
|
||||
#
|
||||
$wgPasswordAttemptThrottle = [
|
||||
// Short term limit
|
||||
[ 'count' => 500, 'seconds' => 300 ],
|
||||
// Long term limit. We need to balance the risk
|
||||
// of somebody using this as a DoS attack to lock someone
|
||||
// out of their account, and someone doing a brute force attack.
|
||||
[ 'count' => 1500, 'seconds' => 60 * 60 * 48 ],
|
||||
];
|
||||
# do not bother to throttle login attempts
|
||||
# users MUST have a valid OIDC token so brute force will get them nowhere.
|
||||
$wgPasswordAttemptThrottle = false;
|
||||
|
||||
# Looks like mediawiki is using undefined constants.... Let's shut that up
|
||||
error_reporting(E_ALL ^ E_NOTICE);
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue