We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents 125e37d + 131c762 commit f66ae67Copy full SHA for f66ae67
1 file changed
packages/fxa-auth-server/config/rate-limit-rules.txt
@@ -193,6 +193,8 @@ passwordlessSendOtp : ip : 100 : 24 hou
193
194
# Passwordless OTP Verification Limits
195
passwordlessVerifyOtp : ip_email : 5 : 10 minutes : 15 minutes : block
196
+passwordlessVerifyOtp : email : 10 : 10 minutes : 30 minutes : report
197
passwordlessVerifyOtp : ip : 100 : 24 hours : 15 minutes : ban
198
passwordlessVerifyOtpPerDay : ip_email : 10 : 24 hours : 24 hours : block
199
+passwordlessVerifyOtpPerDay : email : 20 : 24 hours : 24 hours : report
200
passwordlessVerifyOtpPerDay : ip : 100 : 24 hours : 15 minutes : ban
0 commit comments