Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion assets/data/search-index.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion docs-src/guides/common-CAPABILITIES.md
Original file line number Diff line number Diff line change
Expand Up @@ -196,7 +196,7 @@ A full identity building-block set you compose when you want it; a fresh app run
### Credentials

- **Password security.** PBKDF2-HMAC-SHA512 with 600,000 iterations, a 32-byte salt, and constant-time verification as the only supported algorithm ([ADR-102](../adr/102-pbkdf2-only-password-hashing.md)), pinned by known-answer tests.
- **Brute-force protection is five configured numbers.** `ILoginProtectionService` applies per-email lockout with exponential backoff and a per-IP registration rate limit on cache-backed atomic counters keyed on normalized identity, so capitalization cannot defeat the backoff.
- **Brute-force protection is five configured numbers.** `ILoginProtectionService` applies per-email lockout with exponential backoff and a per-IP registration rate limit on cache-backed counters keyed on normalized identity, so capitalization cannot defeat the backoff. The counters are read-modify-write rather than atomic (an accepted trade-off): sequential guessing trips the limits, while a burst of truly concurrent attempts can slip under them.
- **Reset tokens are hashed, capped, and throttled.** `IPasswordResetTokenService` keeps one active token per address, stores only its digest, discards it after a bounded number of wrong guesses, and throttles requests per email per window, all on cache TTL with no schema and no sweeper ([ADR-091](../adr/091-cache-backed-password-reset.md)).
- **External OAuth.** Google, GitHub, and Apple via `AddExternalAuthProviders`, each gated independently on its `ClientId`, with a ten-minute `ExternalLogin` cookie carrying the external principal to completion, GitHub's email scope requested explicitly, Apple's ES256 client secret minted from key material rather than a static secret, and a `POST exchange` action for the native mobile callback.

Expand Down
2 changes: 1 addition & 1 deletion docs/guides/common-CAPABILITIES.html
Original file line number Diff line number Diff line change
Expand Up @@ -404,7 +404,7 @@ <h3 id="tokens-and-trust">Tokens and trust</h3>
<h3 id="credentials">Credentials</h3>
<ul>
<li><strong>Password security.</strong> PBKDF2-HMAC-SHA512 with 600,000 iterations, a 32-byte salt, and constant-time verification as the only supported algorithm (<a href="../adr/102-pbkdf2-only-password-hashing.html">ADR-102</a>), pinned by known-answer tests.</li>
<li><strong>Brute-force protection is five configured numbers.</strong> <code>ILoginProtectionService</code> applies per-email lockout with exponential backoff and a per-IP registration rate limit on cache-backed atomic counters keyed on normalized identity, so capitalization cannot defeat the backoff.</li>
<li><strong>Brute-force protection is five configured numbers.</strong> <code>ILoginProtectionService</code> applies per-email lockout with exponential backoff and a per-IP registration rate limit on cache-backed counters keyed on normalized identity, so capitalization cannot defeat the backoff. The counters are read-modify-write rather than atomic (an accepted trade-off): sequential guessing trips the limits, while a burst of truly concurrent attempts can slip under them.</li>
<li><strong>Reset tokens are hashed, capped, and throttled.</strong> <code>IPasswordResetTokenService</code> keeps one active token per address, stores only its digest, discards it after a bounded number of wrong guesses, and throttles requests per email per window, all on cache TTL with no schema and no sweeper (<a href="../adr/091-cache-backed-password-reset.html">ADR-091</a>).</li>
<li><strong>External OAuth.</strong> Google, GitHub, and Apple via <code>AddExternalAuthProviders</code>, each gated independently on its <code>ClientId</code>, with a ten-minute <code>ExternalLogin</code> cookie carrying the external principal to completion, GitHub&#39;s email scope requested explicitly, Apple&#39;s ES256 client secret minted from key material rather than a static secret, and a <code>POST exchange</code> action for the native mobile callback.</li>
</ul>
Expand Down
6 changes: 3 additions & 3 deletions sitemap.xml
Original file line number Diff line number Diff line change
Expand Up @@ -182,7 +182,7 @@
</url>
<url>
<loc>https://ivanball.github.io/docs/adr/029-authentication-brute-force-protection.html</loc>
<lastmod>2026-10-03</lastmod>
<lastmod>2026-10-04</lastmod>
<priority>0.6</priority>
</url>
<url>
Expand Down Expand Up @@ -957,7 +957,7 @@
</url>
<url>
<loc>https://ivanball.github.io/docs/guides/adc-specifications.html</loc>
<lastmod>2026-10-03</lastmod>
<lastmod>2026-10-04</lastmod>
<priority>0.6</priority>
</url>
<url>
Expand All @@ -972,7 +972,7 @@
</url>
<url>
<loc>https://ivanball.github.io/docs/guides/common-CAPABILITIES.html</loc>
<lastmod>2026-09-20</lastmod>
<lastmod>2026-10-04</lastmod>
<priority>0.6</priority>
</url>
<url>
Expand Down
Loading