Skip to content

Commit cb2860a

Browse files
authored
Merge pull request #19526 from mozilla/FXA-12471
bug(settings): Fix rate-limit rule on mfa verify code
2 parents a9ac27c + 41fa0cd commit cb2860a

1 file changed

Lines changed: 5 additions & 4 deletions

File tree

packages/fxa-auth-server/config/rate-limit-rules.txt

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -144,10 +144,11 @@ recoveryPhoneSendSigninCode : ip : 100 : 24 hou
144144
# the counts that effect 2FA activity.
145145
#
146146
mfaOtpCodeRequestForEmail : uid : 10 : 5 minutes : 15 minutes : block
147-
mfaVerifyOtpCodeForEmail : uid : 5 : 5 minutes : 15 minutes : block
148147
mfaOtpCodeRequestFor2fa : uid : 10 : 5 minutes : 15 minutes : block
149-
mfaVerifyOtpCodeFor2fa : uid : 5 : 5 minutes : 15 minutes : block
150148
mfaOtpCodeRequestForPassword : uid : 10 : 5 minutes : 15 minutes : block
151-
mfaVerifyOtpCodeForPassword : uid : 5 : 5 minutes : 15 minutes : block
152149
mfaOtpCodeRequestForRecoveryKey : uid : 10 : 5 minutes : 15 minutes : block
153-
mfaVerifyOtpCodeForRecoveryKey : uid : 5 : 5 minutes : 15 minutes : block
150+
# Verify Code rate limits
151+
mfaOtpCodeVerifyForEmail : uid : 5 : 5 minutes : 15 minutes : block
152+
mfaOtpCodeVerifyFor2fa : uid : 5 : 5 minutes : 15 minutes : block
153+
mfaOtpCodeVerifyForPassword : uid : 5 : 5 minutes : 15 minutes : block
154+
mfaOtpCodeVerifyForRecoveryKey : uid : 5 : 5 minutes : 15 minutes : block

0 commit comments

Comments
 (0)