Closed
Description
Describe the feature you'd like
Currently, there is no rate limit for resetting passwords. Unlimited addresses can be entered.
An idea is to limit the resetting password feature for IP's that requests new passwords for non-existing accounts.
Describe the benefits this would bring to existing BookStack users
More security due to blocking malafide requests.
Can the goal of this request already be achieved via other means?
A captcha method.
Logging resets for unknown emails addresses (like logging failed access) to block the IP via failed2ban.
Have you searched for an existing open/closed issue?
- I have searched for existing issues and none cover my fundamental request
How long have you been using BookStack?
1 to 5 years
Additional context
No response