CHANGELOG + REPORT: wger lockout fix, three apps measured (R-752)
gates / gates (push) Successful in 3s
gates / gates (push) Successful in 3s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,15 @@
|
||||
## Strangers cannot lock a whole household out of wger; three other apps measured (2026-10-01, afternoon)
|
||||
|
||||
- **wger** `82fff32` (R-752; `09` §3 decision 58, decided by CC unattended — operator may reverse):
|
||||
`AXES_LOCKOUT_PARAMETERS=username`, `AXES_COOLOFF_TIME=5`, `AXES_HANDLER=axes.handlers.database.AxesDatabaseHandler`.
|
||||
Behind the tunnel every visitor has one address (R-753), so axes' default (by address) let a stranger's 10 wrong tries
|
||||
lock out EVERY member for 30 min — measured on 9202. Now only the targeted name, 5 min (wger 2.7 restarts the lock on
|
||||
every try during it — measured at 15 min: retries kept it closed 40+ min). Settings only — no ladder entry (gates OK).
|
||||
An installed wger takes it at its next Restart/Start, Update or backup restart (measured: the env changed at Restart).
|
||||
- **BookStack** (1.0 min) and **Grafana** (5.0 min): measured, unchanged (decisions 59, 60). **calibre-web**: its 40-a-day
|
||||
lock per name measured (only a restart clears it); waits for the operator. Evidence
|
||||
`felhom.eu/documentation/audits/lockouts-2026-10-01/`.
|
||||
|
||||
## The first full monthly re-test (decision 55); the digest resolver, the outline fixture, the re-test's start (2026-10-01)
|
||||
|
||||
- **The monthly re-test now covers every app with a proven ladder** (`09` §3 decisions 54, 55; R-743). First full run:
|
||||
|
||||
Reference in New Issue
Block a user