Lockouts (R-752): decisions 58-60 (decided by CC unattended), the one address behind the tunnel (R-753), the registry answered (R-750); STATUS, report, evidence
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-01 12:49:20 +02:00
parent 92a60c62bd
commit 8dab40c7a7
14 changed files with 287 additions and 41 deletions
@@ -637,6 +637,31 @@ R-636's louder repeated alarm.
every hour. Catalog `a4597cd`.
**Operator, 2026-10-01 (afternoon): kept** — mealie stays on the 1-hour lock; no secret login name (option d not taken).
### 2026-10-01 (afternoon) — decided by CC unattended, operator may reverse (R-752)
The question for all three: how long may a stranger's wrong passwords, aimed at a PUBLIC login name, keep the household
out? Behind the tunnel every visitor has one address (R-753), so no fix may lean on the visitor's address or on any
header a client can send. Each measured on 9202 (`audits/lockouts-2026-10-01/B/`).
58. **wger: lock only the targeted name, for 5 minutes, counted in the database** — `AXES_LOCKOUT_PARAMETERS=username`,
`AXES_COOLOFF_TIME=5`, `AXES_HANDLER=axes.handlers.database.AxesDatabaseHandler` (catalog `82fff32`). **Options:** (a)
keep ip_address — 10 wrong tries lock EVERY member for 30 min (measured: the second member locked too); (b) username,
30 min; (c) username, 5 min; (d) axes off — no guard. **Why (c):** wger 2.7 hard-codes
`AXES_RESET_COOL_OFF_ON_FAILURE_DURING_LOCKOUT = True`, so every try during a lock restarts it — measured: retrying
every 8 minutes kept a 15-minute lock closed for 40+ minutes; at 5 minutes one retry still let the household in at
7.5 min. The guard stays: 10 tries per 5 minutes per name. The database handler answers axes' own warning W001 (the
default cache is per process) and keeps the count over a restart.
59. **BookStack: no change** — its throttle is 5 tries then 60 s, hard-coded (`ThrottlesLogins.php:82,90`), keyed
`email|ip` where ip is traefik's (`APP_PROXIES` empty), so in effect per name. Measured: locked 1.0 min, then the
right password works. `APP_PROXIES` would only move the key to the tunnel's one address (R-753) — no gain.
60. **Grafana: no change** — per name, 5 failures in a sliding 5 minutes (`loginattemptimpl/login_attempt.go:14`,
`defaults.ini:498-507`); a blocked try is not counted and a successful login resets the count. Measured: locked 5.0
min; under a one-try-a-minute trickle the household got in after the burst aged out. The lock shows as "wrong
password" to the household (Grafana hides it). Raising the attempt limit would not stop a script and weakens the guard.
calibre-web-automated is NOT decided here: its only long lock (40 tries a day per name, `cps/web.py:2218`) has no knob for
its length, and both fixes cost something the household would notice — operator decision in STATUS.
### 2026-09-30 (day) — operator notes, recorded before the work
- **The day brief runs by day.** Every backup and automatic-update test is started by hand — the night chain's debug