Fix typo in documentation
This commit is contained in:
@@ -1,14 +1,14 @@
|
||||
Bruteforce Protection
|
||||
=====================
|
||||
Brute Force Protection
|
||||
======================
|
||||
|
||||
The brute force protection of Kanboard works at the user account level:
|
||||
|
||||
- After 3 authentication failure for the same username, the login form show a captcha image to prevent automated bot tentatives.
|
||||
- After 3 authentication failure for the same username, the login form shows a captcha image to prevent automated bot tentatives.
|
||||
- After 6 authentication failure, the user account is locked down for a period of 15 minutes.
|
||||
|
||||
This feature works only for authentication methods that use the login form.
|
||||
|
||||
However, **after 3 authentication failure through the user API**, the account have to be unlocked by using the login form.
|
||||
However, **after three authentication failure through the user API**, the account has to be unlocked by using the login form.
|
||||
|
||||
Kanboard doesn't block any IP addresses since bots can use several anonymous proxies. However, you can use external tools like [fail2ban](http://www.fail2ban.org) to avoid massive scans.
|
||||
|
||||
@@ -21,6 +21,6 @@ define('BRUTEFORCE_CAPTCHA', 3);
|
||||
// Lock the account after 6 authentication failure
|
||||
define('BRUTEFORCE_LOCKDOWN', 6);
|
||||
|
||||
// Lock account duration in minute
|
||||
// Lock account duration in minutes
|
||||
define('BRUTEFORCE_LOCKDOWN_DURATION', 15);
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user