summaryrefslogtreecommitdiffstats
path: root/start-wekan.sh
diff options
context:
space:
mode:
authorLauri Ojansivu <x@xet7.org>2019-03-11 19:47:23 +0200
committerLauri Ojansivu <x@xet7.org>2019-03-11 19:47:23 +0200
commitb7c000b78b9af253fb115bbfa5ef0d4c0681abbb (patch)
tree837580a319f01b5a3649410e95524f0402443dba /start-wekan.sh
parent4ac8247db06bbd029467226e86393046b160b1ed (diff)
downloadwekan-b7c000b78b9af253fb115bbfa5ef0d4c0681abbb.tar.gz
wekan-b7c000b78b9af253fb115bbfa5ef0d4c0681abbb.tar.bz2
wekan-b7c000b78b9af253fb115bbfa5ef0d4c0681abbb.zip
Changed brute force protection package from eluck:accounts-lockout to
lucasantoniassi:accounts-lockout that is maintained and works. Added Snap/Docker/Source settings. Thanks to xet7 ! Closes #1572, closes #1821
Diffstat (limited to 'start-wekan.sh')
-rwxr-xr-xstart-wekan.sh10
1 files changed, 10 insertions, 0 deletions
diff --git a/start-wekan.sh b/start-wekan.sh
index 184be575..a791944e 100755
--- a/start-wekan.sh
+++ b/start-wekan.sh
@@ -43,6 +43,16 @@ function wekan_repo_check(){
# Wekan Export Board works when WITH_API=true.
# If you disable Wekan API with false, Export Board does not work.
export WITH_API='true'
+ #---------------------------------------------------------------
+ # ==== PASSWORD BRUTE FORCE PROTECTION ====
+ #https://atmospherejs.com/lucasantoniassi/accounts-lockout
+ #Defaults below. Uncomment to change. wekan/server/accounts-lockout.js
+ #export ACCOUNTS_LOCKOUT_KNOWN_USERS_FAILURES_BEFORE=3
+ #export ACCOUNTS_LOCKOUT_KNOWN_USERS_PERIOD=60
+ #export ACCOUNTS_LOCKOUT_KNOWN_USERS_FAILURE_WINDOW=15
+ #export ACCOUNTS_LOCKOUT_UNKNOWN_USERS_FAILURES_BERORE=3
+ #export ACCOUNTS_LOCKOUT_UNKNOWN_USERS_LOCKOUT_PERIOD=60
+ #export ACCOUNTS_LOCKOUT_UNKNOWN_USERS_FAILURE_WINDOW=15
#---------------------------------------------
# CORS: Set Access-Control-Allow-Origin header. Example: *
#export CORS=*