Skip to content

docs(capabilities): login-protection counters are not atomic - #236

Merged
ivanball merged 1 commit into
mainfrom
docs/login-protection-counters-not-atomic
Oct 4, 2026
Merged

ivanball merged 1 commit into
mainfrom
docs/login-protection-counters-not-atomic

Conversation

@ivanball

@ivanball ivanball commented Oct 4, 2026

Copy link
Copy Markdown
Owner

common-CAPABILITIES.md called the login-protection counters "cache-backed atomic counters". LoginProtectionService.IncrementFailedAttemptsAsync documents a read-modify-write increment as an accepted trade-off, so the guide now says that sequential guessing trips the limits and a burst of truly concurrent attempts can slip under them.

Found by ADC Local Test Run 5 (U-23). Render regenerated with npm run build.

🤖 Generated with Claude Code

https://claude.ai/code/session_012sDGvYdTD88ZjjD7if2SMW

The brute-force section called the counters atomic; LoginProtectionService
documents a read-modify-write increment as an accepted trade-off. Found by
ADC Local Test Run 5 (U-23).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012sDGvYdTD88ZjjD7if2SMW
@ivanball
ivanball merged commit 90377e7 into main Oct 4, 2026
4 checks passed
@ivanball
ivanball deleted the docs/login-protection-counters-not-atomic branch October 4, 2026 23:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant